CVE-2024-0641Deadlock in Kernel

Severity
5.5MEDIUMNVD
EPSS
0.0%
top 99.46%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 17
Latest updateFeb 23

Description

A denial of service vulnerability was found in tipc_crypto_key_revoke in net/tipc/crypto.c in the Linux kernel’s TIPC subsystem. This flaw allows guests with local user privileges to trigger a deadlock and potentially crash the system.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages2 packages

NVDlinux/linux_kernel< 6.6+1
Debianlinux/linux_kernel< 5.10.205-1+3

Also affects: Enterprise Linux 8.0, 9.0

Patches

🔴Vulnerability Details

3
GHSA
GHSA-x4v6-w9v4-p32j: A denial of service vulnerability was found in tipc_crypto_key_revoke in net/tipc/crypto2024-01-17
OSV
CVE-2024-0641: A denial of service vulnerability was found in tipc_crypto_key_revoke in net/tipc/crypto2024-01-17
CVEList
Kernel: deadlock leading to denial of service in tipc_crypto_key_revoke2024-01-17

📋Vendor Advisories

10
Ubuntu
Linux kernel (Azure) vulnerabilities2024-02-23
Ubuntu
Linux kernel (Intel IoTG) vulnerabilities2024-02-15
Ubuntu
Linux kernel (Azure) vulnerabilities2024-02-15
Ubuntu
Linux kernel vulnerabilities2024-02-14
Ubuntu
Linux kernel (Intel IoTG) vulnerabilities2024-02-09

💬Community

1
Bugzilla
CVE-2024-0641 kernel: deadlock leading to denial of service in tipc_crypto_key_revoke2024-01-17
CVE-2024-0641 — Deadlock in Linux Kernel | cvebase