---
id: CVE-2024-26800
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  tls: fix use-after-free on failed backlog decryption

  When the decrypt request goes to the backlog and crypto_aead_decrypt
  returns -EBUSY, tls_do_decryption will wait u…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  tls: fix use-after-free on failed backlog decryption

  When the decrypt request goes to the backlog and crypto_aead_decrypt
  returns -EBUSY, tls_do_decryption will wait u…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-416
vendor: linux
product: linux_kernel
affected:
  - 'linux_kernel >= 5.15.160, < 5.16'
  - 'linux_kernel >= 6.6.18, < 6.6.21'
  - 'linux_kernel >= 6.7.6, < 6.7.9'
  - linux_kernel = 6.8
patched:
  - linux_kernel 6.7.9
published: '2024-04-04'
updated: '2026-08-04'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-26800'
references:
  - url: 'https://git.kernel.org/stable/c/13114dc5543069f7b97991e3b79937b6da05f5b0'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/1ac9fb84bc7ecd4bc6428118301d9d864d2a58d1'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/81be85353b0f5a7b660635634b655329b429eefe'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/f2b85a4cc763841843de693bbd7308fe9a2c4c89'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/13114dc5543069f7b97991e3b79937b6da05f5b0'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://git.kernel.org/stable/c/1ac9fb84bc7ecd4bc6428118301d9d864d2a58d1'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://git.kernel.org/stable/c/81be85353b0f5a7b660635634b655329b429eefe'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://git.kernel.org/stable/c/f2b85a4cc763841843de693bbd7308fe9a2c4c89'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00739
epssPercentile: 0.52617
ingestedAt: '2026-08-05T10:46:49.122Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

tls: fix use-after-free on failed backlog decryption

When the decrypt request goes to the backlog and crypto_aead_decrypt
returns -EBUSY, tls_do_decryption will wait until all async
decryptions have completed. If one of them fails, tls_do_decryption
will return -EBADMSG and tls_decrypt_sg jumps to the error path,
releasing all the pages. But the pages have been passed to the async
callback, and have already been released by tls_decrypt_done.

The only true async case is when crypto_aead_decrypt returns
 -EINPROGRESS. With -EBUSY, we already waited so we can tell
tls_sw_recvmsg that the data is available for immediate copy, but we
need to notify tls_decrypt_sg (via the new ->async_done flag) that the
memory has already been released.

## Affected

- `linux_kernel >= 5.15.160, < 5.16`
- `linux_kernel >= 6.6.18, < 6.6.21`
- `linux_kernel >= 6.7.6, < 6.7.9`
- `linux_kernel = 6.8`

## Remediation

Upgrade past the affected range:

- `linux_kernel 6.7.9`
