Review reviewCritical

CVE-2026-64047

Linux

In the Linux kernel, the following vulnerability has been resolved: net: tls: fix off-by-one in sg_chain entry count for wrapped sk_msg ring When an sk_msg scatterlist ring wraps (sg.end < sg.start), tls_push_record() chains the tail portion of the ring to the head using sg_chain(). An extra entry in the sg array is reserved for this: struct sk_msg_sg { [...] /* The extra two elements: * 1) used for chaining the front and sections when the list becomes * partitioned (e.g. end < start). The crypto APIs require the * chaining; * 2) to chain tailer SG entries after the message. */ struct scatt...

CVSS
9.8
EPSS
-
- percentile
CISA KEV
Not listed
Published
2026.07.20
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability-
Technical severityCVSS 9.8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: net: tls: fix off-by-one in sg_chain entry count for wrapped sk_msg ring When an sk_msg scatterlist ring wraps (sg.end < sg.start), tls_push_record() chains the tail portion of the ring to the head using sg_chain(). An extra entry in the sg array is reserved for this: struct sk_msg_sg { [...] /* The extra two elements: * 1) used for chaining the front and sections when the list becomes * partitioned (e.g. end < start). The crypto APIs require the * chaining; * 2) to chain tailer SG entries after the message. */ struct scatt...

Affected product and versions

Product
Linux
Affected versions
>= 9aaaa56845a06aeabdd597cbe19492dc01f281ec < 73963a375885d5ccb7def39fd0b4f542e0f343dd, >= 9aaaa56845a06aeabdd597cbe19492dc01f281ec < 47110c3a9ac247b688657337f5981efcfcb240dc, >= 9aaaa56845a06aeabdd597cbe19492dc01f281ec < 84158c2997159df4a0d70cd9c46774512d32a522, >= 9aaaa56845a06aeabdd597cbe19492dc01f281ec < 131ef12057d92b77b636321b7849c69222405a97, >= 9aaaa56845a06aeabdd597cbe19492dc01f281ec < 66339b71f105e6f83e0da3b9583d95077534fe1d, >= 9aaaa56845a06aeabdd597cbe19492dc01f281ec < eca989eab4b2599dcb02f72140a7c08f08838520, >= 9aaaa56845a06aeabdd597cbe19492dc01f281ec < 2fb0dc7e0099686c4e9d2732745d8a31b18c3628, >= 9aaaa56845a06aeabdd597cbe19492dc01f281ec < 285943c6e7ca309bbea84b253745154241d9788a, >= d529d6c9f7e3aaeac13c4948f79799ccb825f29d, >= 5.4.14 < 5.5, >= 5.5
Fixed versions
No verified fixed-version field is available yet

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE
Not available
CVE-2026-64047 — Linux | SECUFOCUS NOW