cbcvebase.
CVE-2024-26585
published 2024-02-21

CVE-2024-26585: In the Linux kernel, the following vulnerability has been resolved: tls: fix race between tx work scheduling and socket close Similarly to previous commit, the…

PriorityP416medium4.7CVSS 3.1
AVLACHPRLUINSUCNINAH
EPSS
0.59%
45.3th percentile
In the Linux kernel, the following vulnerability has been resolved: tls: fix race between tx work scheduling and socket close Similarly to previous commit, the submitting thread (recvmsg/sendmsg) may exit as soon as the async crypto handler calls complete(). Reorder scheduling the work before calling complete(). This seems more logical in the first place, as it's the inverse order of what the submitting thread will do.

Affected

27 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.85-1 (bookworm)linux 6.1.85-1 (bookworm)
linuxlinux
linuxlinux>= a42055e8d2c30d4decfc13ce943d09c7b9dad221 < dd32621f19243f89ce830919496a5dcc2158aa33dd32621f19243f89ce830919496a5dcc2158aa33
linuxlinux>= a42055e8d2c30d4decfc13ce943d09c7b9dad221 < 196f198ca6fce04ba6ce262f5a0e4d567d7d219d196f198ca6fce04ba6ce262f5a0e4d567d7d219d
linuxlinux>= a42055e8d2c30d4decfc13ce943d09c7b9dad221 < 6db22d6c7a6dc914b12c0469b94eb639b6a8a1466db22d6c7a6dc914b12c0469b94eb639b6a8a146
linuxlinux>= a42055e8d2c30d4decfc13ce943d09c7b9dad221 < e327ed60bff4a991cd7a709c47c4f0c5b4a4fd57e327ed60bff4a991cd7a709c47c4f0c5b4a4fd57
linuxlinux>= a42055e8d2c30d4decfc13ce943d09c7b9dad221 < e01e3934a1b2d122919f73bc6ddbe1cdafc4bbdbe01e3934a1b2d122919f73bc6ddbe1cdafc4bbdb
linuxlinux_kernel>= 0 < 6.1.85-16.1.85-1
linuxlinux_kernel>= 0 < 6.7.7-16.7.7-1
linuxlinux_kernel>= 0 < 6.7.7-16.7.7-1
linuxlinux_kernel>= 0 < 5.4.0-190.2105.4.0-190.210
linuxlinux_kernel>= 0 < 5.15.0-112.1225.15.0-112.122
linuxlinux_kernel>= 0 < 4.4.0-257.2914.4.0-257.291
linuxlinux_kernel>= 0 < 4.15.0-227.2394.15.0-227.239
linuxlinux_kernel>= 0 < 5.4.0-190.2105.4.0-190.210
linuxlinux_kernel>= 0 < 5.15.0-117.1275.15.0-117.127
linuxlinux_kernel>= 0 < 6.8.0-39.396.8.0-39.39
linuxlinux_kernel>= 4.20.0 < 6.6.186.6.18
linuxlinux_kernel>= 6.7.0 < 6.7.66.7.6
msrcazl3_kernel_6.6.14.1-4_on_azure_linux_3.0
msrcazl3_kernel_6.6.22.1-2_on_azure_linux_3.0
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64
msrccbl2_kernel_5.15.158.2-1_on_cbl_mariner_2.0
msrccbl2_kernel_5.15.180.1-1_on_cbl_mariner_2.0

CVSS provenance

nvdv3.14.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian4.7MEDIUM
vendor_msrc4.7MEDIUM
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.