PT-2024-1848 · Linux+11 · Linux Kernel+11
Valis
·
Published
2024-02-10
·
Updated
2026-03-14
·
CVE-2024-26585
CVSS v3.1
7.0
High
| Vector | AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
The issue is related to a synchronization error when using a shared resource in the Linux kernel's tls encrypt done function. This can lead to a denial of service. The problem arises from a race between tx work scheduling and socket close, where the submitting thread may exit as soon as the async crypto handler calls complete. To fix this, the scheduling of work is reordered to occur before calling complete, which is a more logical approach.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
DoS
Race Condition
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Almalinux
Astra Linux
Centos
Debian
Linuxmint
Linux Kernel
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu