THREATOPS
THREAT OPSThreat News › [NVD] CVE-2025-38616 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: tls: handle data disappearing from under the TLS ULP TLS expects that it owns the receive queue of the TCP socket. This cannot be guaranteed in case the reader of the TCP socket entered before the TLS ULP was i

[NVD] CVE-2025-38616 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: tls: handle data disappearing from under the TLS ULP TLS expects that it owns the receive queue of the TCP socket. This cannot be guaranteed in case the reader of the TCP socket entered before the TLS ULP was i

lownvdPublished 2025-08-22

CVE-2025-38616 CVSS: 7.8 HIGH Published: 2025-08-22T14:15:46.017

In the Linux kernel, the following vulnerability has been resolved:

tls: handle data disappearing from under the TLS ULP

TLS expects that it owns the receive queue of the TCP socket. This cannot be guaranteed in case the reader of the TCP socket entered before the TLS ULP was installed, or uses some non-standard read API (eg. zero

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-38616