CVE-2025-38616

tls: handle data disappearing from under the TLS ULP

References

Notes

 carnil> Introduced in 84c61fe1a75b ("tls: rx: do not use the standard strparser").
 carnil> Vulnerable versions: 6.0.

Bugs

Status

Branch Status
upstream released (6.17-rc2) [6db015fc4b5d5f63a64a193f65d98da3a7fc811d]
6.18-upstream-stable N/A "Fixed before branching point"
6.17-upstream-stable N/A "Fixed before branching point"
6.16-upstream-stable released (6.16.2) [2fb97ed9e2672b4f6e24ce206ac1a875ce4bcb38]
6.15-upstream-stable released (6.15.11) [db3658a12d5ec4db7185ae7476151a50521b7207]
6.12-upstream-stable released (6.12.43) [eb0336f213fe88bbdb7d2b19c9c9ec19245a3155]
6.6-upstream-stable released (6.6.103) [f1fe99919f629f980d0b8a7ff16950bffe06a859]
6.1-upstream-stable needed
5.10-upstream-stable N/A "Vulnerable code not present"
sid released (6.16.3-1)
6.12-trixie-security released (6.12.43-1)
6.1-bookworm-security needed
5.10-bullseye-security N/A "Vulnerable code not present"