CVE-2026-23414Patch(linux / linux_kernel)

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch linux linux_kernel systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In the Linux kernel, the following vulnerability has been resolved: tls: Purge async_hold in tls_decrypt_async_wait() The async_hold queue pins encrypted input skbs while the AEAD engine references their scatterlist data. Once tls_decrypt_async_wait() returns, every AEAD operation has completed and the engine no longer references those skbs, so they can be freed unconditionally. A subsequent patch adds batch async decryption to tls_sw_read_sock(), introducing a new call site that must drain pending AEAD operations and release held skbs. Move __skb_queue_purge(&ctx->async_hold) into tls_decrypt_async_wait() so the purge is centralized and every caller -- recvmsg's drain path, the -EBUSY fallback in tls_do_decryption(), and the new read_sock batch path -- releases held skbs on synchronization without each site managing the purge independently. This fixes a leak when tls_strp_msg_hold() fails part-way through, after having added some cloned skbs to the async_hold queue. tls_decrypt_sg() will then call tls_decrypt_async_wait() to process all pending decrypts, and drop back to synchronous mode, but tls_sw_recvmsg() only flushes the async_hold queue when one record has been processed in "fully-async" mode, which may not be the case here. [[email protected]: added leak comment]

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-401

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-04-02); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
linux_kernel

2 versions affected across 1 product

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-04-02: 3Mentions · 2026-04-26: 1Patch / Workaround · 2026-04-02: 1Patch / Workaround · 2026-04-26: 1Technical Details · 2026-04-02: 304-0204-26
Signal classification2 categories
Patch
375.0%
General
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-023
General1Patch2
2026-04-261
Patch1
Full discourse4 posts
  • CVE@CVEnew
    Patch

    CVE-2026-23414 In the Linux kernel, the following vulnerability has been resolved: tls: Purge async_hold in tls_decrypt_async_wait() The async_hold queue pins encrypted input skbs… https://www.cve.org/CVERecord?id=CVE-2026-23414

    Post summary

    CVE‑2026‑23414 affects the Linux kernel's TLS async hold handling and has been fixed by purging the async_hold queue in tls_decrypt_async_wait. No exploitation or PoC information is included.

    00001157
    56.9K followersView on X
  • WindowsForum@windowsforum
    Patch

    🪟 CVE-2026-23414 is a “meh” memory leak, but in WSL2 that’s just reliability roulette for anyone running TLS-heavy stuff. Patch now—before your containers get stuck holding the bag. https://windowsforum.com/threads/cve-2026-23414-linux-ktls-memory-leak-what-windows-users-wsl2-must-patch.415202/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #LinuxKernelSecurity #KtlsAndTls #Cve202623414 #Wsl2Patching https://t.co/iblx8x71e9

    Post summary

    The post highlights CVE-2026-23414, a memory‑leak vulnerability impacting WSL2 TLS workloads, and urges users to apply a patch before container failures occur.

    0000044
    1.1K followersView on X
  • Infoflowcloud@infoflowcloud
    Patch

    🚨*CVE* CVE-2026-23414 In the Linux kernel, the following vulnerability has been resolved: tls: Purge async_hold in tls_decrypt_async_wait() The async_hold queue pins encrypted input skbs… https://www.cve.org/CVERecord?id=CVE-2026-23414 ----- Traducción: CVE-2026-23414 En … http://infoflow.cloud`

    Post summary

    The post states that CVE-2026-23414 in the Linux kernel has been resolved, referencing the affected function, but does not provide a patch link or explicit remediation details.

    0000036
    65 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    General

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-23414 - tls: Purge async_hold in tls_decrypt_async_wait() Intel Report: https://ift.tt/bIfcY8i

    Post summary

    An alert notes the existence of CVE‑2026‑23414 with a brief technical description, but offers no information on exploitation, PoC, or patches.

    000002.1K
    281 followersView on X
CPE platform detail9 entries

9 of 9 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---
OSlinuxlinux_kernel6.18--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--

Explore more