CVE-2024-0646Out-of-bounds Write in Kernel

Severity
7.8HIGHNVD
CNA7.0
EPSS
0.0%
top 95.94%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 17
Latest updateApr 8

Description

An out-of-bounds memory write flaw was found in the Linux kernel’s Transport Layer Security functionality in how a user calls a function splice with a ktls socket as the destination. This flaw allows a local user to crash or potentially escalate their privileges on the system.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages3 packages

NVDlinux/linux_kernel4.205.4.267+5
Debianlinux/linux_kernel< 5.10.209-1+3
Palo Altopaloalto/pan-os

Also affects: Enterprise Linux 8.0, 9.0

Patches

🔴Vulnerability Details

3
CVEList
Kernel: ktls overwrites readonly memory pages when using function splice with a ktls socket as destination2024-01-17
GHSA
GHSA-qmff-49xc-7rf6: An out-of-bounds memory write flaw was found in the Linux kernel’s Transport Layer Security functionality in how a user calls a function splice with a2024-01-17
OSV
CVE-2024-0646: An out-of-bounds memory write flaw was found in the Linux kernel’s Transport Layer Security functionality in how a user calls a function splice with a2024-01-17

📋Vendor Advisories

18
Palo Alto
PAN-SA-2026-0006 Informational Bulletin: Impact assessment of OSS CVEs in PAN-OS2026-04-08
Ubuntu
Kernel Live Patch Security Notice2024-04-03
Ubuntu
Kernel Live Patch Security Notice2024-03-12
Chrome
Long Term Support Channel Update for ChromeOS: CVE-2024-06462024-03-05
Ubuntu
Linux kernel (GKE) vulnerabilities2024-03-04

💬Community

2
Bugzilla
CVE-2024-26761 kernel: cxl/pci: Fix disabling memory if DVSEC CXL Range does not match a CFMWS window2024-04-04
Bugzilla
CVE-2024-0646 kernel: ktls overwrites readonly memory pages when using function splice with a ktls socket as destination2023-12-10
CVE-2024-0646 — Out-of-bounds Write in Linux Kernel | cvebase