Answer in brief
CVE-2026-80904 records a Unknown severity vulnerability in net/tls: Fail tls_sw_splice_read() after a failed async decrypt. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=f314bfee81b1bf8e01168177b2f65f24eb8da63a <a808aadff634c7a408b2ab84d5919e9a741fdb5b || >=f314bfee81b1bf8e01168177b2f65f24eb8da63a <06c2a53604fa1dc4820063828d7dadb3675b7af8 || >=f314bfee81b1bf8e01168177b2f65f24eb8da63a <18ae1e95f20867106a28820c208a9cec99dda861 || >=f314bfee81b1bf8e01168177b2f65f24eb8da63a <82d9269f01ebfd835b6256aa17016a974cbbc647 || >=f314bfee81b1bf8e01168177b2f65f24eb8da63a <4b177911eb9f799e9841c2f87c75b08cb112757a || >=f314bfee81b1bf8e01168177b2f65f24eb8da63a <976df67f463db1fddaf2a32fb04f57ad2891a23d | a808aadff634c7a408b2ab84d5919e9a741fdb5b, 06c2a53604fa1dc4820063828d7dadb3675b7af8, 18ae1e95f20867106a28820c208a9cec99dda861, 82d9269f01ebfd835b6256aa17016a974cbbc647, 4b177911eb9f799e9841c2f87c75b08cb112757a, 976df67f463db1fddaf2a32fb04f57ad2891a23d |
| Linux/Linuxgeneric | 5.19 | Not reported |
Published upstream
Sep 4, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 4, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 4, 2026
In the Linux kernel, the following vulnerability has been resolved: net/tls: Fail tls_sw_splice_read() after a failed async decrypt When an async decrypt fails, tls_decrypt_done() records the error in ctx->async_wait.err and calls tls_err_abort(), which stores it in sk_err. tls_sw_recvmsg() and tls_sw_read_sock() each read async_wait.err once they hold the reader lock and fail the call: a record that did not authenticate breaks the connection. tls_sw_splice_read() has no such check, and sk_err does not stand in for one. tls_rx_rec_wait() tests sk_err only inside the loop it skips whenever a record is already parsed, and the first reader to reach sock_error() clears it, while async_wait.err persists. A splice therefore keeps delivering records on a connection that recvmsg() and read_sock() refuse to read. Read async_wait.err in tls_sw_splice_read() as the other two readers do.
Quoted source text, attributed separately from HOL analysis.