Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-Id: <DIZLR1S1UFXC.1CL0O1X3GAEZ9@redcoat.dev>
Date: Wed, 03 Jun 2026 18:49:23 +0100
From: "Emily Shepherd" <emily@...coat.dev>
To: <oss-security@...ts.openwall.com>, <jcb62281@...il.com>
Subject: Re: Linux kernel TLS ULP use-after-free in
 tls_sk_proto_close()

On Wed Jun 3, 2026 at 10:16 AM BST, Oleg Sevostyanov wrote:
> Thank you for the comments.
>
> You are right about the reproducer. I mistakenly included it despite saying
> that I was not including it. I apologize for the inconsistency.

This reads like AI. Given the original mistake in publicly submitting 
a PoC when you intended not to, I have to ask: is a human properly 
checking the contents of the emails you are sending?

> I also agree that taking lock_sock(sk) earlier in tls_sk_proto_close() 
> looks
> like the natural mitigation direction, given that the function takes it
> unconditionally anyway. I will bring this point to the kernel/networking
> maintainers when discussing a fix.

Can you clarify if this has been raised on the appropriate kernel 
mailing lists? I do not see it in your timeline:

On Tues Jun 2, 2026 at 20:59 AM BST, Oleg Sevostyanov wrote:
> Timeline:
> 2026-05-16: Reported to linux-distros
> 2026-05-30: Latest agreed public disclosure date
> 2026-06-02: Public disclosure to oss-security

Emily

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.