{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.1.176-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.12.94-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "7.0.12-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  net: tls: fix off-by-one in sg_chain entry count for wrapped sk_msg ring  When an sk_msg scatterlist ring wraps (sg.end \u003c sg.start), tls_push_record() chains the tail portion of the ring to the head using sg_chain(). An extra entry in the sg array is reserved for this:    struct sk_msg_sg {         [...]         /* The extra two elements:          * 1) used for chaining the front and sections when the list becomes          *    partitioned (e.g. end \u003c start). The crypto APIs require the          *    chaining;          * 2) to chain tailer SG entries after the message.          */         struct scatterlist              data[MAX_MSG_FRAGS + 2];  The current code uses MAX_SKB_FRAGS + 1 as the ring size:      sg_chain(\u0026msg_pl-\u003esg.data[msg_pl-\u003esg.start],              MAX_SKB_FRAGS - msg_pl-\u003esg.start + 1,              msg_pl-\u003esg.data);  This places the chain pointer at    sg_chain(data[start], (MAX_SKB_FRAGS - msg_start + 1) .. =   \u0026data[start] + (MAX_SKB_FRAGS - msg_start + 1) - 1 =   data[start + (MAX_SKB_FRAGS - start + 1) - 1] =   data[MAX_SKB_FRAGS]  instead of the true last entry. This is likely due to a \"race\" of the commit under Fixes landing close to commit 031097d9e079 (\"bpf: sk_msg, zap ingress queue on psock down\")  Convert to ARRAY_SIZE and drop the data[start] / - start (as suggested by Sabrina).",
  "id": "DEBIAN-CVE-2026-64047",
  "modified": "2026-09-14T16:47:28.074243873Z",
  "published": "2026-07-19T16:17:45.053Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-64047"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ],
  "upstream": [
    "CVE-2026-64047"
  ]
}