CVE-2024-26584Improper Handling of Exceptional Conditions in Linux

Severity
5.5MEDIUMNVD
OSV7.8OSV7.5OSV7.0OSV6.5
EPSS
0.0%
top 90.69%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 21
Latest updateAug 22

Description

In the Linux kernel, the following vulnerability has been resolved: net: tls: handle backlogging of crypto requests Since we're setting the CRYPTO_TFM_REQ_MAY_BACKLOG flag on our requests to the crypto API, crypto_aead_{encrypt,decrypt} can return -EBUSY instead of -EINPROGRESS in valid situations. For example, when the cryptd queue for AESNI is full (easy to trigger with an artificially low cryptd.cryptd_max_cpu_qlen), requests will be enqueued to the backlog but still processed. In that case

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages7 packages

NVDlinux/linux_kernel4.16.06.1.84+2
Debianlinux/linux_kernel< 6.1.85-1+2
Ubuntulinux/linux_kernel< 5.4.0-190.210+1
CVEListV5linux/linuxa54667f6728c2714a400f3c884727da74b6d17173ade391adc584f17b5570fd205de3ad029090368+5
debiandebian/linux< linux 6.1.85-1 (bookworm)

Patches

🔴Vulnerability Details

25
OSV
linux-raspi-5.4 vulnerabilities2024-08-22
OSV
linux-oracle, linux-oracle-5.4 vulnerabilities2024-08-09
OSV
linux-aws, linux-aws-5.4 vulnerabilities2024-07-30
OSV
linux, linux-azure, linux-azure-5.4, linux-bluefield, linux-gcp, linux-gcp-5.4, linux-gkeop, linux-hwe-5.4, linux-ibm, linux-ibm-5.4, linux-iot, linux-kvm, linux-raspi, linux-xilinx-zynqmp vulnerabili2024-07-29
OSV
linux-raspi vulnerabilities2024-07-26

📋Vendor Advisories

25
Ubuntu
Linux kernel (Raspberry Pi) vulnerabilities2024-08-22
Ubuntu
Linux kernel (Oracle) vulnerabilities2024-08-09
Ubuntu
Linux kernel vulnerabilities2024-07-30
Ubuntu
Linux kernel vulnerabilities2024-07-29
Ubuntu
Linux kernel vulnerabilities2024-07-26

💬Community

1
Bugzilla
CVE-2024-26584 kernel: tls: handle backlogging of crypto requests2024-02-22