cbcvebase.
CVE-2024-26583
published 2024-02-21

CVE-2024-26583: In the Linux kernel, the following vulnerability has been resolved: tls: fix race between async notify and socket close The submitting thread (one which called…

PriorityP416medium4.7CVSS 3.1
AVLACHPRLUINSUCNINAH
EPSS
0.55%
43.2th percentile
In the Linux kernel, the following vulnerability has been resolved: tls: fix race between async notify and socket close The submitting thread (one which called recvmsg/sendmsg) may exit as soon as the async crypto handler calls complete() so any code past that point risks touching already freed data. Try to avoid the locking and extra flags altogether. Have the main thread hold an extra reference, this way we can depend solely on the atomic ref counter for synchronization. Don't futz with reiniting the completion, either, we are now tightly controlling when completion fires.

Affected

29 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.82-1 (bookworm)linux 6.1.82-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 0cada33241d9de205522e3858b18e506ca5cce2c < f17d21ea73918ace8afb9c2d8e734dbf71c2c9d7f17d21ea73918ace8afb9c2d8e734dbf71c2c9d7
linuxlinux>= 0cada33241d9de205522e3858b18e506ca5cce2c < 7a3ca06d04d589deec81f56229a9a9d62352ce017a3ca06d04d589deec81f56229a9a9d62352ce01
linuxlinux>= 0cada33241d9de205522e3858b18e506ca5cce2c < 86dc27ee36f558fe223dbdfbfcb6856247356f4a86dc27ee36f558fe223dbdfbfcb6856247356f4a
linuxlinux>= 0cada33241d9de205522e3858b18e506ca5cce2c < 6209319b2efdd8524691187ee99c40637558fa336209319b2efdd8524691187ee99c40637558fa33
linuxlinux>= 0cada33241d9de205522e3858b18e506ca5cce2c < aec7961916f3f9e88766e2688992da6980f11b8daec7961916f3f9e88766e2688992da6980f11b8d
linuxlinux>= 5.4.44 < 5.55.5
linuxlinux>= 5.6.16 < 5.75.7
linuxlinux_kernel>= 0 < 6.1.82-16.1.82-1
linuxlinux_kernel>= 0 < 6.7.7-16.7.7-1
linuxlinux_kernel>= 0 < 6.7.7-16.7.7-1
linuxlinux_kernel>= 0 < 5.4.0-190.2105.4.0-190.210
linuxlinux_kernel>= 0 < 5.15.0-112.1225.15.0-112.122
linuxlinux_kernel>= 5.7.0 < 6.1.796.1.79
linuxlinux_kernel>= 6.2.0 < 6.6.186.6.18
linuxlinux_kernel>= 6.7.0 < 6.7.66.7.6
msrcazl3_hyperv-daemons_6.6.14.1-1_on_azure_linux_3.0
msrcazl3_hyperv-daemons_6.6.22.1-2_on_azure_linux_3.0
msrcazl3_kernel_6.6.14.1-4_on_azure_linux_3.0
msrcazl3_kernel_6.6.22.1-2_on_azure_linux_3.0
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64

CVSS provenance

nvdv3.14.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian4.7MEDIUM
vendor_msrc4.7MEDIUM
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.