Impact
A flaw in the Linux kernel’s TLS stack can produce an off‑by‑one error while chaining the tail of a wrapped sk_msg scatterlist ring. The bug causes the sg_chain function to point to an element past the intended array bounds during tls_push_record(), potentially corrupting kernel memory.
Affected Systems
Linux kernel installations running a version that has not applied the recent patch are vulnerable; no specific vendor version limits were listed in the advisory.
Risk and Exploitability
The vulnerability has a CVSS score of 9.8 and an EPSS score of less than 1 %. It is not listed in CISA’s KEV catalog. The likely attack vector is network‑based, using crafted TLS traffic to trigger the wrap condition; however, the low EPSS indicates that exploitation in the wild is unlikely at this time. Nevertheless, the flaw must be remediated as soon as possible.
OpenCVE Enrichment
Ubuntu USN