We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2024-26585

tls: fix race between tx work scheduling and socket close



AssignerLinux
Reserved2024-02-19
Published2024-02-21
Updated2024-08-19

Description

In the Linux kernel, the following vulnerability has been resolved: tls: fix race between tx work scheduling and socket close Similarly to previous commit, the submitting thread (recvmsg/sendmsg) may exit as soon as the async crypto handler calls complete(). Reorder scheduling the work before calling complete(). This seems more logical in the first place, as it's the inverse order of what the submitting thread will do.

Product status

Default status
0x40029f6960

a42055e8d2c3 before dd32621f1924
affected

a42055e8d2c3 before 196f198ca6fc
affected

a42055e8d2c3 before 6db22d6c7a6d
affected

a42055e8d2c3 before e327ed60bff4
affected

a42055e8d2c3 before e01e3934a1b2
affected

Default status
0x40029f6c50

4.20
affected

Any version before 4.20
unaffected

5.15.165
unaffected

6.1.84
unaffected

6.6.18
unaffected

6.7.6
unaffected

6.8
unaffected

References

https://git.kernel.org/stable/c/dd32621f19243f89ce830919496a5dcc2158aa33

https://git.kernel.org/stable/c/196f198ca6fce04ba6ce262f5a0e4d567d7d219d

https://git.kernel.org/stable/c/6db22d6c7a6dc914b12c0469b94eb639b6a8a146

https://git.kernel.org/stable/c/e327ed60bff4a991cd7a709c47c4f0c5b4a4fd57

https://git.kernel.org/stable/c/e01e3934a1b2d122919f73bc6ddbe1cdafc4bbdb

cve.org CVE-2024-26585

nvd.nist.gov CVE-2024-26585

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2024-26585
Subscribe to our newsletter to learn more about our work.