PT-2023-8408 · Linux+8 · Linux Kernel+8

Jann Horn

·

Published

2023-12-07

·

Updated

2026-02-18

·

CVE-2024-0646

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An out-of-bounds memory write flaw was found in the Linux kernel’s Transport Layer Security functionality. This issue arises when a user calls a function splice with a ktls socket as the destination, allowing a local user to crash or potentially escalate their privileges on the system. The flaw is related to the tls sw sendmsg splice function in the /net/tls/tls sw.c file.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:0897
ALT-PU-2024-10855
ALT-PU-2024-17575
ALT-PU-2024-1867
ALT-PU-2024-2275
AZL-33890
AZL-34873
BDU:2024-00674
CESA-2024_0876
CESA-2024_0881
CESA-2024_0897
CVE-2024-0646
DLA-3841-1
LSN-0101-1
LSN-0102-1
RHSA-2024:0723
RHSA-2024:0724
RHSA-2024:0725
RHSA-2024:0850
RHSA-2024:0851
RHSA-2024:0876
RHSA-2024:0881
RHSA-2024:0897
RHSA-2024:1248
RHSA-2024:1250
RHSA-2024:1251
RHSA-2024:1253
RHSA-2024:1268
RHSA-2024:1269
RHSA-2024:1278
RHSA-2024:1306
RHSA-2024:1367
RHSA-2024:1368
RHSA-2024:1377
RHSA-2024:1382
RHSA-2024:1404
RHSA-2024_0881
RHSA-2024_0897
RHSA-2024_1248
RXSA-2024:1248
USN-6639-1
USN-6648-1
USN-6648-2
USN-6651-1
USN-6651-2
USN-6651-3
USN-6652-1
USN-6653-1
USN-6653-2
USN-6653-3
USN-6653-4

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Linux Kernel
Red Hat
Red Os
Ubuntu