CVE-2024-26585Race Condition in Linux

CWE-362Race Condition54 documents8 sources
Severity
4.7MEDIUMNVD
OSV7.8OSV7.5OSV7.0OSV6.5OSV5.5OSV2.5
EPSS
0.0%
top 90.33%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 21
Latest updateAug 22

Description

In the Linux kernel, the following vulnerability has been resolved: tls: fix race between tx work scheduling and socket close Similarly to previous commit, the submitting thread (recvmsg/sendmsg) may exit as soon as the async crypto handler calls complete(). Reorder scheduling the work before calling complete(). This seems more logical in the first place, as it's the inverse order of what the submitting thread will do.

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.0 | Impact: 3.6

Affected Packages13 packages

Patches

🔴Vulnerability Details

26
OSV
linux-raspi-5.4 vulnerabilities2024-08-22
OSV
Kernel Live Patch Security Notice2024-08-20
OSV
linux-oracle, linux-oracle-5.4 vulnerabilities2024-08-09
OSV
linux-aws, linux-aws-5.4 vulnerabilities2024-07-30
OSV
linux, linux-azure, linux-azure-5.4, linux-bluefield, linux-gcp, linux-gcp-5.4, linux-gkeop, linux-hwe-5.4, linux-ibm, linux-ibm-5.4, linux-iot, linux-kvm, linux-raspi, linux-xilinx-zynqmp vulnerabili2024-07-29

📋Vendor Advisories

26
Ubuntu
Linux kernel (Raspberry Pi) vulnerabilities2024-08-22
Ubuntu
Kernel Live Patch Security Notice2024-08-20
Ubuntu
Linux kernel (Oracle) vulnerabilities2024-08-09
Ubuntu
Linux kernel vulnerabilities2024-07-30
Ubuntu
Linux kernel vulnerabilities2024-07-29

💬Community

1
Bugzilla
CVE-2024-26585 kernel: tls: race between tx work scheduling and socket close2024-02-22