Impact
An out‑of‑bounds write occurs in the Linux kernel TLS device module when TLS offload is used. The flaw allows the kernel to write beyond the bounds of a pre‑allocated fragment array, triggering KASAN and UBSAN checks and ultimately leading to a kernel panic and system crash. The vulnerability can destabilise the affected system and potentially expose the attacker to denial‑of‑service and privilege escalation if the crash is exploited to manipulate kernel memory during the side‑effects of the panic.
Affected Systems
Linux kernel versions using the net/tls/tls_device.c module with TLS offload enabled. The issue is only reachable on machines that have a network interface card implementing TLS offload; no specific vendor product is listed beyond the Linux kernel itself.
Risk and Exploitability
The vulnerability has a severity that results in a kernel Oops, but the exploitability is limited to hosts with TLS offload NICs and requires the kernel to be vectored to the right execution path. EPSS data is not available and the bug is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a local or privileged attacker interacting with a TLS offload device or a remote attacker able to trigger the kernel path via crafted traffic to the offload. The exploit would cause a crash and could be used to pivot to higher privileges if the system recovers in a compromised state.
OpenCVE Enrichment
Debian DLA