CVE-2024-0646
published 2024-01-17CVE-2024-0646: An out-of-bounds memory write flaw was found in the Linux kernel’s Transport Layer Security functionality in how a user calls a function splice with a ktls…
PriorityP345high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.31%
23.1th percentile
An out-of-bounds memory write flaw was found in the Linux kernel’s Transport Layer Security functionality in how a user calls a function splice with a ktls socket as the destination. This flaw allows a local user to crash or potentially escalate their privileges on the system.
Affected
29 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.69-1 (bookworm) | linux 6.1.69-1 (bookworm) |
| chrome_chrome | — | — | |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.10.209-1 | 5.10.209-1 |
| linux | linux_kernel | >= 0 < 6.1.69-1 | 6.1.69-1 |
| linux | linux_kernel | >= 0 < 6.6.8-1 | 6.6.8-1 |
| linux | linux_kernel | >= 0 < 6.6.8-1 | 6.6.8-1 |
| linux | linux_kernel | >= 0 < 5.4.0-172.190 | 5.4.0-172.190 |
| linux | linux_kernel | >= 0 < 5.15.0-97.107 | 5.15.0-97.107 |
| linux | linux_kernel | >= 0 < 4.4.0-251.285 | 4.4.0-251.285 |
| linux | linux_kernel | >= 0 < 4.4.0-252.286 | 4.4.0-252.286 |
| linux | linux_kernel | >= 0 < 4.15.0-222.233 | 4.15.0-222.233 |
| linux | linux_kernel | >= 0 < 4.15.0-223.235 | 4.15.0-223.235 |
| linux | linux_kernel | >= 0 < 5.4.0-172.190 | 5.4.0-172.190 |
| linux | linux_kernel | >= 0 < 5.4.0-174.193 | 5.4.0-174.193 |
| linux | linux_kernel | >= 0 < 5.15.0-97.107 | 5.15.0-97.107 |
| linux | linux_kernel | >= 0 < 5.15.0-101.111 | 5.15.0-101.111 |
| linux | linux_kernel | >= 4.20 < 5.4.267 | 5.4.267 |
| linux | linux_kernel | >= 5.11 < 5.15.147 | 5.15.147 |
| linux | linux_kernel | >= 5.16 < 6.1.69 | 6.1.69 |
| linux | linux_kernel | >= 5.5 < 5.10.208 | 5.10.208 |
| linux | linux_kernel | >= 6.2 < 6.6.7 | 6.6.7 |
| msrc | azl3_kernel_6.6.35.1-4_on_azure_linux_3.0 | — | — |
| msrc | azl3_kernel_6.6.47.1-1_on_azure_linux_3.0 | — | — |
| msrc | cbl2_kernel_5.15.153.1-1_on_cbl_mariner_2.0 | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_msrc7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian7.0HIGH
vendor_redhat7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Kernel Live Patch Security Notice
osv·2024-04-03·CVSS 7.0
CVE-2023-1872 [HIGH] Kernel Live Patch Security Notice
Kernel Live Patch Security Notice
It was discovered that a race condition existed in the io_uring subsystem
in the Linux kernel, leading to a use-after-free vulnerability. A local
attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code.(CVE-2023-1872)
Lonial Con discovered that the netfilter subsystem in the Linux kernel
contained a memory leak when handling certain element flush operations. A
local attacker could use this to expose sensitive information (kernel
memory).(CVE-2023-4569)
It was discovered that the TLS subsystem in the Linux kernel did not
properly perform cryptographic operations in some situations, leading to a
null pointer dereference vulnerability. A local attacker could use this to
cause a denial of service (system crash)
OSV
Kernel Live Patch Security Notice
osv·2024-03-12·CVSS 7.8
CVE-2023-6817 [HIGH] Kernel Live Patch Security Notice
Kernel Live Patch Security Notice
Xingyuan Mo discovered that the netfilter subsystem in the Linux kernel did
not properly handle inactive elements in its PIPAPO data structure, leading
to a use-after-free vulnerability. A local attacker could use this to cause
a denial of service (system crash) or possibly execute arbitrary code.(CVE-2023-6817)
It was discovered that the IGMP protocol implementation in the Linux kernel
contained a race condition, leading to a use-after-free vulnerability. A
local attacker could use this to cause a denial of service (system crash)
or possibly execute arbitrary code.(CVE-2023-6932)
It was discovered that the netfilter connection tracker for netlink in the
Linux kernel did not properly perform reference counting in some error
conditions. A local attacker
OSV
linux-gke vulnerabilities
osv·2024-03-04·CVSS 7.0
CVE-2023-51780 [HIGH] linux-gke vulnerabilities
linux-gke vulnerabilities
It was discovered that a race condition existed in the ATM (Asynchronous
Transfer Mode) subsystem of the Linux kernel, leading to a use-after-free
vulnerability. A local attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code. (CVE-2023-51780)
It was discovered that a race condition existed in the AppleTalk networking
subsystem of the Linux kernel, leading to a use-after-free vulnerability. A
local attacker could use this to cause a denial of service (system crash)
or possibly execute arbitrary code. (CVE-2023-51781)
Zhenghan Wang discovered that the generic ID allocator implementation in
the Linux kernel did not properly check for null bitmap when releasing IDs.
A local attacker could use this to cause a denial of
OSV
linux-starfive-6.5 vulnerabilities
osv·2024-02-29·CVSS 7.0
CVE-2023-51780 [HIGH] linux-starfive-6.5 vulnerabilities
linux-starfive-6.5 vulnerabilities
It was discovered that a race condition existed in the ATM (Asynchronous
Transfer Mode) subsystem of the Linux kernel, leading to a use-after-free
vulnerability. A local attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code. (CVE-2023-51780)
It was discovered that a race condition existed in the AppleTalk networking
subsystem of the Linux kernel, leading to a use-after-free vulnerability. A
local attacker could use this to cause a denial of service (system crash)
or possibly execute arbitrary code. (CVE-2023-51781)
Zhenghan Wang discovered that the generic ID allocator implementation in
the Linux kernel did not properly check for null bitmap when releasing IDs.
A local attacker could use this to cause a
OSV
linux-lowlatency vulnerabilities
osv·2024-02-29·CVSS 7.0
CVE-2023-51780 [HIGH] linux-lowlatency vulnerabilities
linux-lowlatency vulnerabilities
It was discovered that a race condition existed in the ATM (Asynchronous
Transfer Mode) subsystem of the Linux kernel, leading to a use-after-free
vulnerability. A local attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code. (CVE-2023-51780)
It was discovered that a race condition existed in the AppleTalk networking
subsystem of the Linux kernel, leading to a use-after-free vulnerability. A
local attacker could use this to cause a denial of service (system crash)
or possibly execute arbitrary code. (CVE-2023-51781)
Zhenghan Wang discovered that the generic ID allocator implementation in
the Linux kernel did not properly check for null bitmap when releasing IDs.
A local attacker could use this to cause a de
OSV
linux-aws, linux-aws-5.15 vulnerabilities
osv·2024-02-28·CVSS 7.0
CVE-2023-51780 [HIGH] linux-aws, linux-aws-5.15 vulnerabilities
linux-aws, linux-aws-5.15 vulnerabilities
It was discovered that a race condition existed in the ATM (Asynchronous
Transfer Mode) subsystem of the Linux kernel, leading to a use-after-free
vulnerability. A local attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code. (CVE-2023-51780)
It was discovered that a race condition existed in the AppleTalk networking
subsystem of the Linux kernel, leading to a use-after-free vulnerability. A
local attacker could use this to cause a denial of service (system crash)
or possibly execute arbitrary code. (CVE-2023-51781)
Zhenghan Wang discovered that the generic ID allocator implementation in
the Linux kernel did not properly check for null bitmap when releasing IDs.
A local attacker could use this to c
OSV
linux-azure, linux-azure-5.4 vulnerabilities
osv·2024-02-28·CVSS 7.0
CVE-2023-51781 [HIGH] linux-azure, linux-azure-5.4 vulnerabilities
linux-azure, linux-azure-5.4 vulnerabilities
It was discovered that a race condition existed in the AppleTalk networking
subsystem of the Linux kernel, leading to a use-after-free vulnerability. A
local attacker could use this to cause a denial of service (system crash)
or possibly execute arbitrary code. (CVE-2023-51781)
Zhenghan Wang discovered that the generic ID allocator implementation in
the Linux kernel did not properly check for null bitmap when releasing IDs.
A local attacker could use this to cause a denial of service (system
crash). (CVE-2023-6915)
Robert Morris discovered that the CIFS network file system implementation
in the Linux kernel did not properly validate certain server commands
fields, leading to an out-of-bounds read vulnerability. An attacker could
use this to c
OSV
linux-lowlatency, linux-lowlatency-hwe-6.5, linux-oem-6.5 vulnerabilities
osv·2024-02-28·CVSS 7.0
CVE-2023-51780 [HIGH] linux-lowlatency, linux-lowlatency-hwe-6.5, linux-oem-6.5 vulnerabilities
linux-lowlatency, linux-lowlatency-hwe-6.5, linux-oem-6.5 vulnerabilities
It was discovered that a race condition existed in the ATM (Asynchronous
Transfer Mode) subsystem of the Linux kernel, leading to a use-after-free
vulnerability. A local attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code. (CVE-2023-51780)
It was discovered that a race condition existed in the AppleTalk networking
subsystem of the Linux kernel, leading to a use-after-free vulnerability. A
local attacker could use this to cause a denial of service (system crash)
or possibly execute arbitrary code. (CVE-2023-51781)
Zhenghan Wang discovered that the generic ID allocator implementation in
the Linux kernel did not properly check for null bitmap when releasing IDs.
A lo
OSV
linux, linux-azure, linux-azure-5.15, linux-azure-fde, linux-azure-fde-5.15, linux-gcp, linux-gcp-5.15, linux-gkeop, linux-gkeop-5.15, linux-hwe-5.15, linux-ibm, linux-ibm-5.15, linux-intel-iotg, linu
osv·2024-02-23·CVSS 7.0
[HIGH] linux, linux-azure, linux-azure-5.15, linux-azure-fde, linux-azure-fde-5.15, linux-gcp, linux-gcp-5.15, linux-gkeop, linux-gkeop-5.15, linux-hwe-5.15, linux-ibm, linux-ibm-5.15, linux-intel-iotg, linu
linux, linux-azure, linux-azure-5.15, linux-azure-fde, linux-azure-fde-5.15, linux-gcp, linux-gcp-5.15, linux-gkeop, linux-gkeop-5.15, linux-hwe-5.15, linux-ibm, linux-ibm-5.15, linux-intel-iotg, linux-intel-iotg-5.15, linux-kvm, linux-lowlatency-hwe-5.15, linux-nvidia, linux-oracle, linux-oracle-5.15, linux-raspi vulnerabilities
It was discovered that a race condition existed in the ATM (Asynchronous
Transfer Mode) subsystem of the Linux kernel, leading to a use-after-free
vulnerability. A local attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code. (CVE-2023-51780)
It was discovered that a race condition existed in the AppleTalk networking
subsystem of the Linux kernel, leading to a use-after-free vulnerability. A
local attacker could us
OSV
linux, linux-aws, linux-gcp, linux-hwe-6.5, linux-laptop, linux-oracle, linux-raspi, linux-starfive vulnerabilities
osv·2024-02-23·CVSS 7.0
CVE-2023-51780 [HIGH] linux, linux-aws, linux-gcp, linux-hwe-6.5, linux-laptop, linux-oracle, linux-raspi, linux-starfive vulnerabilities
linux, linux-aws, linux-gcp, linux-hwe-6.5, linux-laptop, linux-oracle, linux-raspi, linux-starfive vulnerabilities
It was discovered that a race condition existed in the ATM (Asynchronous
Transfer Mode) subsystem of the Linux kernel, leading to a use-after-free
vulnerability. A local attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code. (CVE-2023-51780)
It was discovered that a race condition existed in the AppleTalk networking
subsystem of the Linux kernel, leading to a use-after-free vulnerability. A
local attacker could use this to cause a denial of service (system crash)
or possibly execute arbitrary code. (CVE-2023-51781)
Zhenghan Wang discovered that the generic ID allocator implementation in
the Linux kernel did not properly chec
OSV
linux-azure vulnerabilities
osv·2024-02-23·CVSS 4.9
CVE-2023-34324 [MEDIUM] linux-azure vulnerabilities
linux-azure vulnerabilities
Marek Marczykowski-Górecki discovered that the Xen event channel
infrastructure implementation in the Linux kernel contained a race
condition. An attacker in a guest VM could possibly use this to cause a
denial of service (paravirtualized device unavailability). (CVE-2023-34324)
Zheng Wang discovered a use-after-free in the Renesas Ethernet AVB driver
in the Linux kernel during device removal. A privileged attacker could use
this to cause a denial of service (system crash). (CVE-2023-35827)
Tom Dohrmann discovered that the Secure Encrypted Virtualization (SEV)
implementation for AMD processors in the Linux kernel contained a race
condition when accessing MMIO registers. A local attacker in a SEV guest VM
could possibly use this to cause a denial of service (s
OSV
linux, linux-aws, linux-aws-5.4, linux-bluefield, linux-gcp, linux-gcp-5.4, linux-gkeop, linux-hwe-5.4, linux-ibm, linux-ibm-5.4, linux-iot, linux-kvm, linux-oracle, linux-oracle-5.4, linux-raspi, lin
osv·2024-02-22·CVSS 7.0
[HIGH] linux, linux-aws, linux-aws-5.4, linux-bluefield, linux-gcp, linux-gcp-5.4, linux-gkeop, linux-hwe-5.4, linux-ibm, linux-ibm-5.4, linux-iot, linux-kvm, linux-oracle, linux-oracle-5.4, linux-raspi, lin
linux, linux-aws, linux-aws-5.4, linux-bluefield, linux-gcp, linux-gcp-5.4, linux-gkeop, linux-hwe-5.4, linux-ibm, linux-ibm-5.4, linux-iot, linux-kvm, linux-oracle, linux-oracle-5.4, linux-raspi, linux-raspi-5.4, linux-xilinx-zynqmp vulnerabilities
It was discovered that a race condition existed in the AppleTalk networking
subsystem of the Linux kernel, leading to a use-after-free vulnerability. A
local attacker could use this to cause a denial of service (system crash)
or possibly execute arbitrary code. (CVE-2023-51781)
Zhenghan Wang discovered that the generic ID allocator implementation in
the Linux kernel did not properly check for null bitmap when releasing IDs.
A local attacker could use this to cause a denial of service (system
crash). (CVE-2023-6915)
Robert Morris discovered t
OSV
linux-oem-6.1 vulnerabilities
osv·2024-02-15·CVSS 7.0
CVE-2023-51780 [HIGH] linux-oem-6.1 vulnerabilities
linux-oem-6.1 vulnerabilities
It was discovered that a race condition existed in the ATM (Asynchronous
Transfer Mode) subsystem of the Linux kernel, leading to a use-after-free
vulnerability. A local attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code. (CVE-2023-51780)
It was discovered that a race condition existed in the AppleTalk networking
subsystem of the Linux kernel, leading to a use-after-free vulnerability. A
local attacker could use this to cause a denial of service (system crash)
or possibly execute arbitrary code. (CVE-2023-51781)
It was discovered that a race condition existed in the Rose X.25 protocol
implementation in the Linux kernel, leading to a use-after- free
vulnerability. A local attacker could use this to cause a
GHSA
GHSA-qmff-49xc-7rf6: An out-of-bounds memory write flaw was found in the Linux kernel’s Transport Layer Security functionality in how a user calls a function splice with a
ghsa_unreviewed·2024-01-17
CVE-2024-0646 [HIGH] CWE-1314 GHSA-qmff-49xc-7rf6: An out-of-bounds memory write flaw was found in the Linux kernel’s Transport Layer Security functionality in how a user calls a function splice with a
An out-of-bounds memory write flaw was found in the Linux kernel’s Transport Layer Security functionality in how a user calls a function splice with a ktls socket as the destination. This flaw allows a local user to crash or potentially escalate their privileges on the system.
OSV
CVE-2024-0646: An out-of-bounds memory write flaw was found in the Linux kernel’s Transport Layer Security functionality in how a user calls a function splice with a
osv·2024-01-17·CVSS 7.8
CVE-2024-0646 [HIGH] CVE-2024-0646: An out-of-bounds memory write flaw was found in the Linux kernel’s Transport Layer Security functionality in how a user calls a function splice with a
An out-of-bounds memory write flaw was found in the Linux kernel’s Transport Layer Security functionality in how a user calls a function splice with a ktls socket as the destination. This flaw allows a local user to crash or potentially escalate their privileges on the system.
Palo Alto
PAN-SA-2026-0006 Informational Bulletin: Impact assessment of OSS CVEs in PAN-OS
vendor_paloalto·2026-04-08·CVSS 7.8
CVE-2023-2176 [HIGH] PAN-SA-2026-0006 Informational Bulletin: Impact assessment of OSS CVEs in PAN-OS
PAN-SA-2026-0006 Informational Bulletin: Impact assessment of OSS CVEs in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS software. While PAN-OS software may include the
CVEs: CVE-2023-2176, CVE-2023-28464, CVE-2023-5633, CVE-2024-0646, CVE-2024-36886, CVE-2024-36971, CVE-2025-57052
Affected products: PAN-OS
CISA ICS
Siemens SINEC OS
cisa_ics·2025-08-14
Siemens SINEC OS
ICS Advisory
##
Siemens SINEC OS
Release DateAugust 14, 2025
Alert CodeICSA-25-226-15
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3.1 9.1
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: RUGGEDCOM, SCALANCE
- Vulnerabilities: NULL Pointer Dereference, Use After Free, Unchecked Input for Loop Condition, Out-of-bounds Write, Ou
Ubuntu
Kernel Live Patch Security Notice
vendor_ubuntu·2024-04-03·CVSS 7.8
CVE-2023-6176 [HIGH] Kernel Live Patch Security Notice
Title: Kernel Live Patch Security Notice
Summary: Several security issues were fixed in the kernel.
It was discovered that a race condition existed in the io_uring subsystem
in the Linux kernel, leading to a use-after-free vulnerability. A local
attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code.(CVE-2023-1872)
Lonial Con discovered that the netfilter subsystem in the Linux kernel
contained a memory leak when handling certain element flush operations. A
local attacker could use this to expose sensitive information (kernel
memory).(CVE-2023-4569)
It was discovered that the TLS subsystem in the Linux kernel did not
properly perform cryptographic operations in some situations, leading to a
null pointer dereference vulnerability. A local
Ubuntu
Kernel Live Patch Security Notice
vendor_ubuntu·2024-03-12·CVSS 7.8
CVE-2023-6817 [HIGH] Kernel Live Patch Security Notice
Title: Kernel Live Patch Security Notice
Summary: Several security issues were fixed in the kernel.
Xingyuan Mo discovered that the netfilter subsystem in the Linux kernel did
not properly handle inactive elements in its PIPAPO data structure, leading
to a use-after-free vulnerability. A local attacker could use this to cause
a denial of service (system crash) or possibly execute arbitrary code.(CVE-2023-6817)
It was discovered that the IGMP protocol implementation in the Linux kernel
contained a race condition, leading to a use-after-free vulnerability. A
local attacker could use this to cause a denial of service (system crash)
or possibly execute arbitrary code.(CVE-2023-6932)
It was discovered that the netfilter connection tracker for netlink in the
Linux kernel did not properly per
Chrome
Long Term Support Channel Update for ChromeOS: CVE-2024-0646
vendor_chrome·2024-03-05·CVSS 7.0
CVE-2024-0646 [HIGH] Long Term Support Channel Update for ChromeOS: CVE-2024-0646
Long Term Support Channel Update for ChromeOS
CVE-2024-0646
Ubuntu
Linux kernel (GKE) vulnerabilities
vendor_ubuntu·2024-03-04·CVSS 7.0
CVE-2024-0565 [HIGH] Linux kernel (GKE) vulnerabilities
Title: Linux kernel (GKE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that a race condition existed in the ATM (Asynchronous
Transfer Mode) subsystem of the Linux kernel, leading to a use-after-free
vulnerability. A local attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code. (CVE-2023-51780)
It was discovered that a race condition existed in the AppleTalk networking
subsystem of the Linux kernel, leading to a use-after-free vulnerability. A
local attacker could use this to cause a denial of service (system crash)
or possibly execute arbitrary code. (CVE-2023-51781)
Zhenghan Wang discovered that the generic ID allocator implementation in
the Linux kernel did not properly check for nu
Ubuntu
Linux kernel (StarFive) vulnerabilities
vendor_ubuntu·2024-02-29·CVSS 7.0
CVE-2024-0565 [HIGH] Linux kernel (StarFive) vulnerabilities
Title: Linux kernel (StarFive) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that a race condition existed in the ATM (Asynchronous
Transfer Mode) subsystem of the Linux kernel, leading to a use-after-free
vulnerability. A local attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code. (CVE-2023-51780)
It was discovered that a race condition existed in the AppleTalk networking
subsystem of the Linux kernel, leading to a use-after-free vulnerability. A
local attacker could use this to cause a denial of service (system crash)
or possibly execute arbitrary code. (CVE-2023-51781)
Zhenghan Wang discovered that the generic ID allocator implementation in
the Linux kernel did not properly check f
Ubuntu
Linux kernel (Low Latency) vulnerabilities
vendor_ubuntu·2024-02-29·CVSS 7.0
CVE-2023-51780 [HIGH] Linux kernel (Low Latency) vulnerabilities
Title: Linux kernel (Low Latency) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that a race condition existed in the ATM (Asynchronous
Transfer Mode) subsystem of the Linux kernel, leading to a use-after-free
vulnerability. A local attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code. (CVE-2023-51780)
It was discovered that a race condition existed in the AppleTalk networking
subsystem of the Linux kernel, leading to a use-after-free vulnerability. A
local attacker could use this to cause a denial of service (system crash)
or possibly execute arbitrary code. (CVE-2023-51781)
Zhenghan Wang discovered that the generic ID allocator implementation in
the Linux kernel did not properly chec
Ubuntu
Linux kernel (AWS) vulnerabilities
vendor_ubuntu·2024-02-28·CVSS 7.0
CVE-2024-0646 [HIGH] Linux kernel (AWS) vulnerabilities
Title: Linux kernel (AWS) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that a race condition existed in the ATM (Asynchronous
Transfer Mode) subsystem of the Linux kernel, leading to a use-after-free
vulnerability. A local attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code. (CVE-2023-51780)
It was discovered that a race condition existed in the AppleTalk networking
subsystem of the Linux kernel, leading to a use-after-free vulnerability. A
local attacker could use this to cause a denial of service (system crash)
or possibly execute arbitrary code. (CVE-2023-51781)
Zhenghan Wang discovered that the generic ID allocator implementation in
the Linux kernel did not properly check for nu
Ubuntu
Linux kernel (Azure) vulnerabilities
vendor_ubuntu·2024-02-28·CVSS 7.0
CVE-2023-51781 [HIGH] Linux kernel (Azure) vulnerabilities
Title: Linux kernel (Azure) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that a race condition existed in the AppleTalk networking
subsystem of the Linux kernel, leading to a use-after-free vulnerability. A
local attacker could use this to cause a denial of service (system crash)
or possibly execute arbitrary code. (CVE-2023-51781)
Zhenghan Wang discovered that the generic ID allocator implementation in
the Linux kernel did not properly check for null bitmap when releasing IDs.
A local attacker could use this to cause a denial of service (system
crash). (CVE-2023-6915)
Robert Morris discovered that the CIFS network file system implementation
in the Linux kernel did not properly validate certain server commands
fields, leading to an
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2024-02-28·CVSS 7.0
CVE-2024-0565 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that a race condition existed in the ATM (Asynchronous
Transfer Mode) subsystem of the Linux kernel, leading to a use-after-free
vulnerability. A local attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code. (CVE-2023-51780)
It was discovered that a race condition existed in the AppleTalk networking
subsystem of the Linux kernel, leading to a use-after-free vulnerability. A
local attacker could use this to cause a denial of service (system crash)
or possibly execute arbitrary code. (CVE-2023-51781)
Zhenghan Wang discovered that the generic ID allocator implementation in
the Linux kernel did not properly check for null bit
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2024-02-23·CVSS 7.0
CVE-2023-51781 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that a race condition existed in the ATM (Asynchronous
Transfer Mode) subsystem of the Linux kernel, leading to a use-after-free
vulnerability. A local attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code. (CVE-2023-51780)
It was discovered that a race condition existed in the AppleTalk networking
subsystem of the Linux kernel, leading to a use-after-free vulnerability. A
local attacker could use this to cause a denial of service (system crash)
or possibly execute arbitrary code. (CVE-2023-51781)
Zhenghan Wang discovered that the generic ID allocator implementation in
the Linux kernel did not properly check for null bit
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2024-02-23·CVSS 7.0
CVE-2024-0565 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that a race condition existed in the ATM (Asynchronous
Transfer Mode) subsystem of the Linux kernel, leading to a use-after-free
vulnerability. A local attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code. (CVE-2023-51780)
It was discovered that a race condition existed in the AppleTalk networking
subsystem of the Linux kernel, leading to a use-after-free vulnerability. A
local attacker could use this to cause a denial of service (system crash)
or possibly execute arbitrary code. (CVE-2023-51781)
Zhenghan Wang discovered that the generic ID allocator implementation in
the Linux kernel did not properly check for null bit
Ubuntu
Linux kernel (Azure) vulnerabilities
vendor_ubuntu·2024-02-23·CVSS 4.9
CVE-2023-46862 [MEDIUM] Linux kernel (Azure) vulnerabilities
Title: Linux kernel (Azure) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Marek Marczykowski-Górecki discovered that the Xen event channel
infrastructure implementation in the Linux kernel contained a race
condition. An attacker in a guest VM could possibly use this to cause a
denial of service (paravirtualized device unavailability). (CVE-2023-34324)
Zheng Wang discovered a use-after-free in the Renesas Ethernet AVB driver
in the Linux kernel during device removal. A privileged attacker could use
this to cause a denial of service (system crash). (CVE-2023-35827)
Tom Dohrmann discovered that the Secure Encrypted Virtualization (SEV)
implementation for AMD processors in the Linux kernel contained a race
condition when accessing MMIO registers. A local
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2024-02-22·CVSS 7.0
CVE-2023-51781 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that a race condition existed in the AppleTalk networking
subsystem of the Linux kernel, leading to a use-after-free vulnerability. A
local attacker could use this to cause a denial of service (system crash)
or possibly execute arbitrary code. (CVE-2023-51781)
Zhenghan Wang discovered that the generic ID allocator implementation in
the Linux kernel did not properly check for null bitmap when releasing IDs.
A local attacker could use this to cause a denial of service (system
crash). (CVE-2023-6915)
Robert Morris discovered that the CIFS network file system implementation
in the Linux kernel did not properly validate certain server commands
fields, leading to an out-of-b
Ubuntu
Linux kernel (OEM) vulnerabilities
vendor_ubuntu·2024-02-15·CVSS 7.0
CVE-2023-6531 [HIGH] Linux kernel (OEM) vulnerabilities
Title: Linux kernel (OEM) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that a race condition existed in the ATM (Asynchronous
Transfer Mode) subsystem of the Linux kernel, leading to a use-after-free
vulnerability. A local attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code. (CVE-2023-51780)
It was discovered that a race condition existed in the AppleTalk networking
subsystem of the Linux kernel, leading to a use-after-free vulnerability. A
local attacker could use this to cause a denial of service (system crash)
or possibly execute arbitrary code. (CVE-2023-51781)
It was discovered that a race condition existed in the Rose X.25 protocol
implementation in the Linux kernel, leading t
Microsoft
Kernel: ktls overwrites readonly memory pages when using function splice with a ktls socket as destination
vendor_msrc·2024-01-09·CVSS 7.8
CVE-2024-0646 [HIGH] CWE-787 Kernel: ktls overwrites readonly memory pages when using function splice with a ktls socket as destination
Kernel: ktls overwrites readonly memory pages when using function splice with a ktls socket as destination
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
redhat: redhat
Customer Action Required: Yes
Remedi
Debian
CVE-2024-0646: linux - An out-of-bounds memory write flaw was found in the Linux kernel’s Transport Lay...
vendor_debian·2024·CVSS 7.0
CVE-2024-0646 [HIGH] CVE-2024-0646: linux - An out-of-bounds memory write flaw was found in the Linux kernel’s Transport Lay...
An out-of-bounds memory write flaw was found in the Linux kernel’s Transport Layer Security functionality in how a user calls a function splice with a ktls socket as the destination. This flaw allows a local user to crash or potentially escalate their privileges on the system.
Scope: local
bookworm: resolved (fixed in 6.1.69-1)
bullseye: resolved (fixed in 5.10.209-1)
forky: resolved (fixed in 6.6.8-1)
sid: resolved (fixed in 6.6.8-1)
trixie: resolved (fixed in 6.6.8-1)
Red Hat
kernel: ktls overwrites readonly memory pages when using function splice with a ktls socket as destination
vendor_redhat·2023-12-07·CVSS 7.0
CVE-2024-0646 [HIGH] CWE-787 kernel: ktls overwrites readonly memory pages when using function splice with a ktls socket as destination
kernel: ktls overwrites readonly memory pages when using function splice with a ktls socket as destination
An out-of-bounds memory write flaw was found in the Linux kernel’s Transport Layer Security functionality in how a user calls a function splice with a ktls socket as the destination. This flaw allows a local user to crash or potentially escalate their privileges on the system.
An out-of-bounds memory write flaw was found in the Linux kernel’s Transport Layer Security functionality in how a user calls a function splice with a ktls socket as the destination. This flaw allows a local user to crash or potentially escalate their privileges on the system.
Mitigation: To mitigate this issue, prevent module tls from being loaded. Please see https://access.redhat.com/solutions/41278 for how
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2024-26761 kernel: cxl/pci: Fix disabling memory if DVSEC CXL Range does not match a CFMWS window
bugzilla·2024-04-04·CVSS 5.5
CVE-2024-26761 [MEDIUM] CVE-2024-26761 kernel: cxl/pci: Fix disabling memory if DVSEC CXL Range does not match a CFMWS window
CVE-2024-26761 kernel: cxl/pci: Fix disabling memory if DVSEC CXL Range does not match a CFMWS window
In the Linux kernel, the following vulnerability has been resolved:
cxl/pci: Fix disabling memory if DVSEC CXL Range does not match a CFMWS window
The Linux kernel CVE team has assigned CVE-2024-26761 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024040305-CVE-2024-26761-0646@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2273201]
---
The result of automatic check (that is developed by Alexander Larkin) for this CVE-2024-26761 is: CHECK Maybe valid. Check manually. with impact LOW (that is an approximation based on flags INIT ; these flags parsed automatically based on patch data). Such automatic check hap
Bugzilla
CVE-2024-0646 kernel: ktls overwrites readonly memory pages when using function splice with a ktls socket as destination
bugzilla·2023-12-10·CVSS 7.8
CVE-2024-0646 [HIGH] CVE-2024-0646 kernel: ktls overwrites readonly memory pages when using function splice with a ktls socket as destination
CVE-2024-0646 kernel: ktls overwrites readonly memory pages when using function splice with a ktls socket as destination
A flaw in the Linux Kernel found. When splice() is called with a ktls socket as destination, the ktls code fails to update the internal "curr"/"copybreak" accounting that tracks which parts of the plaintext scatter-gather buffer (`struct sk_msg_sg`) are unused writable memory. This can cause subsequent writes to the socket to overwrite the contents of spliced pages, including pages from files to which the caller is not supposed to have write access.
Reference:
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=c5a595000e267
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2258817]
---
Created kernel track
https://access.redhat.com/errata/RHSA-2024:0723https://access.redhat.com/errata/RHSA-2024:0724https://access.redhat.com/errata/RHSA-2024:0725https://access.redhat.com/errata/RHSA-2024:0850https://access.redhat.com/errata/RHSA-2024:0851https://access.redhat.com/errata/RHSA-2024:0876https://access.redhat.com/errata/RHSA-2024:0881https://access.redhat.com/errata/RHSA-2024:0897https://access.redhat.com/errata/RHSA-2024:1248https://access.redhat.com/errata/RHSA-2024:1250https://access.redhat.com/errata/RHSA-2024:1251https://access.redhat.com/errata/RHSA-2024:1253https://access.redhat.com/errata/RHSA-2024:1268https://access.redhat.com/errata/RHSA-2024:1269https://access.redhat.com/errata/RHSA-2024:1278https://access.redhat.com/errata/RHSA-2024:1306https://access.redhat.com/errata/RHSA-2024:1367https://access.redhat.com/errata/RHSA-2024:1368https://access.redhat.com/errata/RHSA-2024:1377https://access.redhat.com/errata/RHSA-2024:1382https://access.redhat.com/errata/RHSA-2024:1404https://access.redhat.com/errata/RHSA-2024:2094https://access.redhat.com/security/cve/CVE-2024-0646https://bugzilla.redhat.com/show_bug.cgi?id=2253908https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=c5a595000e267https://access.redhat.com/errata/RHSA-2024:0723https://access.redhat.com/errata/RHSA-2024:0724https://access.redhat.com/errata/RHSA-2024:0725https://access.redhat.com/errata/RHSA-2024:0850https://access.redhat.com/errata/RHSA-2024:0851https://access.redhat.com/errata/RHSA-2024:0876https://access.redhat.com/errata/RHSA-2024:0881https://access.redhat.com/errata/RHSA-2024:0897https://access.redhat.com/errata/RHSA-2024:1248https://access.redhat.com/errata/RHSA-2024:1250https://access.redhat.com/errata/RHSA-2024:1251https://access.redhat.com/errata/RHSA-2024:1253https://access.redhat.com/errata/RHSA-2024:1268https://access.redhat.com/errata/RHSA-2024:1269https://access.redhat.com/errata/RHSA-2024:1278https://access.redhat.com/errata/RHSA-2024:1306https://access.redhat.com/errata/RHSA-2024:1367https://access.redhat.com/errata/RHSA-2024:1368https://access.redhat.com/errata/RHSA-2024:1377https://access.redhat.com/errata/RHSA-2024:1382https://access.redhat.com/errata/RHSA-2024:1404https://access.redhat.com/errata/RHSA-2024:2094https://access.redhat.com/security/cve/CVE-2024-0646https://bugzilla.redhat.com/show_bug.cgi?id=2253908https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=c5a595000e267https://lists.debian.org/debian-lts-announce/2024/06/msg00016.html
2024-01-17
Published