CVE-2024-26583
MEDIUMLinux Kernel 5.7.0-6.1.78, 5.16.0-5.15.159, 6.2.0-6.6.17, 6.7.0-6.7.5 - Race Condition in TLS Async Notification
Title source: llmDescription
In the Linux kernel, the following vulnerability has been resolved: tls: fix race between async notify and socket close The submitting thread (one which called recvmsg/sendmsg) may exit as soon as the async crypto handler calls complete() so any code past that point risks touching already freed data. Try to avoid the locking and extra flags altogether. Have the main thread hold an extra reference, this way we can depend solely on the atomic ref counter for synchronization. Don't futz with reiniting the completion, either, we are now tightly controlling when completion fires.
References (6)
Core 6
Core References
Mailing List, Third Party Advisory
https://lists.fedoraproject.org/archives/list/[email protected]/message/EZOU3745CWCDZ7EMKMXB2OEEIB5Q3IWM/
Scores
CVSS v3
4.7
EPSS
0.0018
EPSS Percentile
7.3%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-362
Status
published
Products (21)
linux/Kernel
5.16.0 - 6.1.79linux
linux/Kernel
5.7.0 - 5.15.160linux
linux/Kernel
6.2.0 - 6.6.18linux
linux/Kernel
6.7.0 - 6.7.6linux
Linux/Linux
< 5.7
Linux/Linux
0cada33241d9de205522e3858b18e506ca5cce2c - 6209319b2efdd8524691187ee99c40637558fa33
Linux/Linux
0cada33241d9de205522e3858b18e506ca5cce2c - 7a3ca06d04d589deec81f56229a9a9d62352ce01
Linux/Linux
0cada33241d9de205522e3858b18e506ca5cce2c - 86dc27ee36f558fe223dbdfbfcb6856247356f4a
Linux/Linux
0cada33241d9de205522e3858b18e506ca5cce2c - aec7961916f3f9e88766e2688992da6980f11b8d
Linux/Linux
0cada33241d9de205522e3858b18e506ca5cce2c - f17d21ea73918ace8afb9c2d8e734dbf71c2c9d7
... and 11 more
Published
Feb 21, 2024
Tracked Since
Feb 18, 2026