A Linux kernel vulnerability in the TLS ULP subsystem can trigger a use-after-free in tls_sk_proto_close() when one thread closes a TLS socket while another concurrently calls setsockopt(SOL_TLS, TLS_TX). The flaw stems from a race in TLS socket teardown and state manipulation, and the original reporter said a reproducer exists, though it was mistakenly included in a public oss-security posting despite an intention to withhold it until a fix was available. The issue was reportedly shared with linux-distros before a fix had been accepted upstream, with public disclosure occurring later on oss-security.
Follow-up discussion on the mailing list pointed to taking lock_sock(sk) earlier in tls_sk_proto_close() as the most natural mitigation because the function already acquires that lock unconditionally. Reviewers said the bug may reflect a broader locking-order problem worth auditing in similar kernel paths, and the reporter said the proposed locking change would be raised with Linux kernel networking maintainers while a fix is discussed.

See affected versions and whether adversaries are exploiting it.
6 events from the most recent confirmed update back to the earliest known activity.
Aretiq published research describing CVE-2026-3593 in ISC BIND 9's DNS-over-HTTPS implementation, explaining that repeated HTTP/2 SETTINGS changes to INITIAL_WINDOW_SIZE can trigger a use-after-free. The write-up says the issue reliably crashed ASAN-instrumented or hardened builds in testing, while default jemalloc-based production builds did not crash.
ISC fixed the DNS-over-HTTPS HTTP/2 SETTINGS use-after-free vulnerability CVE-2026-3593 in BIND 9 versions 9.20.23, 9.21.22, and 9.20.23-S1. The fix nulls the HTTP/2 response buffer pointer before releasing the request structure.
Oleg Sevostyanov publicly disclosed a Linux kernel TLS ULP race condition that can trigger a use-after-free in tls_sk_proto_close() via close() and setsockopt(SOL_TLS, TLS_TX). Follow-up discussion noted a reproducer was mistakenly included in the public archives despite an intent to withhold it until a fix was available.
The disclosure timeline for the Linux kernel TLS ULP use-after-free listed 2026-05-30 as the latest proposed date for public disclosure. The later oss-security discussion says the eventual public post occurred after that date.
The Linux kernel TLS ULP use-after-free vulnerability was reported to the linux-distros list before a fix had been accepted by kernel maintainers. Multiple oss-security references explicitly state this happened on 2026-05-16.
ISC published a knowledge base advisory for CVE-2022-1183, titled "Destroying a TLS session early causes assertion failure." The reference provides the publication date but no additional event details in the synopsis.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
6 references tracked. Mallory keeps watching after this page renders.
aretiq.ai
Open sourceseclists.org
Open sourceseclists.org
Open sourceseclists.org
Open sourceseclists.org
Open sourcekb.isc.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.