Kernel: ktls overwrites readonly memory pages when using function splice with a ktls socket as destination
Summary
| CVE | CVE-2024-0646 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2024-01-17 16:15:47 UTC |
| Updated | 2026-08-06 22:16:39 UTC |
| Description | An out-of-bounds memory write flaw was found in the Linux kernel’s Transport Layer Security functionality in how a user calls a function splice with a ktls socket as the destination. This flaw allows a local user to crash or potentially escalate their privileges on the system. |
Risk And Classification
Primary CVSS: v3.1 7.8 HIGH from [email protected]
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Problem Types: CWE-787 | CWE-787 Out-of-bounds Write
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | [email protected] | Secondary | 7 | HIGH | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | CNA | CVSS | 7 | HIGH | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
CVSS v3.1 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Linux | Linux Kernel | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Red Hat | Red Hat Enterprise Linux 8 | unaffected 0:4.18.0-513.18.1.rt7.320.el8_9 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 8 | Not specified | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 8 | unaffected 0:4.18.0-513.18.1.el8_9 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 8.2 Advanced Update Support | unaffected 0:4.18.0-193.128.1.el8_2 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 8.2 Telecommunications Update Service | unaffected 0:4.18.0-193.128.1.rt13.179.el8_2 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 8.2 Telecommunications Update Service | unaffected 0:4.18.0-193.128.1.el8_2 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 8.2 Update Services For SAP Solutions | unaffected 0:4.18.0-193.128.1.el8_2 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 8.2 Update Services For SAP Solutions | Not specified | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | unaffected 0:4.18.0-305.125.1.el8_4 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 8.4 Telecommunications Update Service | unaffected 0:4.18.0-305.125.1.rt7.201.el8_4 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 8.4 Telecommunications Update Service | unaffected 0:4.18.0-305.125.1.el8_4 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 8.4 Update Services For SAP Solutions | unaffected 0:4.18.0-305.125.1.el8_4 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 8.4 Update Services For SAP Solutions | Not specified | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 8.6 Extended Update Support | unaffected 0:4.18.0-372.91.1.el8_6 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 8.6 Extended Update Support | Not specified | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 8.8 Extended Update Support | Not specified | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 8.8 Extended Update Support | unaffected 0:4.18.0-477.51.1.el8_8 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 9 | unaffected 0:5.14.0-362.24.1.el9_3 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 9 | unaffected 0:5.14.0-362.24.1.el9_3 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 9 | Not specified | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 9.0 Extended Update Support | unaffected 0:5.14.0-70.93.2.el9_0 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 9.0 Extended Update Support | unaffected 0:5.14.0-70.93.1.rt21.165.el9_0 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 9.0 Extended Update Support | Not specified | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 9.2 Extended Update Support | unaffected 0:5.14.0-284.52.1.el9_2 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 9.2 Extended Update Support | unaffected 0:5.14.0-284.52.1.rt14.337.el9_2 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 9.2 Extended Update Support | Not specified | Not specified |
| CNA | Red Hat | Red Hat Virtualization 4 For Red Hat Enterprise Linux 8 | unaffected 0:4.18.0-372.91.1.el8_6 * rpm | Not specified |
| CNA | Red Hat | RHOL-5.8-RHEL-9 | unaffected v5.8.6-22 * rpm | Not specified |
| CNA | Red Hat | RHOL-5.8-RHEL-9 | unaffected v5.8.6-11 * rpm | Not specified |
| CNA | Red Hat | RHOL-5.8-RHEL-9 | unaffected v6.8.1-407 * rpm | Not specified |
| CNA | Red Hat | RHOL-5.8-RHEL-9 | unaffected v5.8.6-19 * rpm | Not specified |
| CNA | Red Hat | RHOL-5.8-RHEL-9 | unaffected v1.0.0-479 * rpm | Not specified |
| CNA | Red Hat | RHOL-5.8-RHEL-9 | unaffected v5.8.6-7 * rpm | Not specified |
| CNA | Red Hat | RHOL-5.8-RHEL-9 | unaffected v0.4.0-247 * rpm | Not specified |
| CNA | Red Hat | RHOL-5.8-RHEL-9 | unaffected v5.8.6-5 * rpm | Not specified |
| CNA | Red Hat | RHOL-5.8-RHEL-9 | unaffected v1.1.0-227 * rpm | Not specified |
| CNA | Red Hat | RHOL-5.8-RHEL-9 | unaffected v5.8.1-470 * rpm | Not specified |
| CNA | Red Hat | RHOL-5.8-RHEL-9 | unaffected v2.9.6-14 * rpm | Not specified |
| CNA | Red Hat | RHOL-5.8-RHEL-9 | unaffected v5.8.6-2 * rpm | Not specified |
| CNA | Red Hat | RHOL-5.8-RHEL-9 | unaffected v5.8.6-24 * rpm | Not specified |
| CNA | Red Hat | RHOL-5.8-RHEL-9 | unaffected v5.8.6-10 * rpm | Not specified |
| CNA | Red Hat | RHOL-5.8-RHEL-9 | unaffected v0.1.0-525 * rpm | Not specified |
| CNA | Red Hat | RHOL-5.8-RHEL-9 | unaffected v0.1.0-224 * rpm | Not specified |
| CNA | Red Hat | RHOL-5.8-RHEL-9 | unaffected v0.28.1-56 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 6 | Not specified | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 7 | Not specified | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 7 | Not specified | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 9 | Not specified | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| access.redhat.com/errata/RHSA-2024:1404 | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | Third Party Advisory |
| access.redhat.com/errata/RHSA-2024:0876 | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | Third Party Advisory |
| access.redhat.com/errata/RHSA-2024:1268 | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | Third Party Advisory |
| access.redhat.com/errata/RHSA-2024:1250 | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | Third Party Advisory |
| access.redhat.com/errata/RHSA-2024:1377 | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | Third Party Advisory |
| access.redhat.com/errata/RHSA-2024:2094 | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | Third Party Advisory |
| 2253908 – (CVE-2024-0646) CVE-2024-0646 kernel: ktls overwrites readonly memory pages when using function splice with a ktls socket as destination | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | Issue Tracking, Patch |
| lists.debian.org/debian-lts-announce/2024/06/msg00016.html | af854a3a-2127-422b-91ae-364da2661108 | lists.debian.org | |
| access.redhat.com/errata/RHSA-2024:1368 | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | Third Party Advisory |
| access.redhat.com/errata/RHSA-2024:1306 | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | Third Party Advisory |
| access.redhat.com/errata/RHSA-2024:0723 | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | Third Party Advisory |
| access.redhat.com/errata/RHSA-2024:0725 | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | Third Party Advisory |
| access.redhat.com/errata/RHSA-2024:0897 | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | Third Party Advisory |
| access.redhat.com/errata/RHSA-2024:0851 | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | Third Party Advisory |
| access.redhat.com/errata/RHSA-2024:1248 | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | Third Party Advisory |
| access.redhat.com/errata/RHSA-2024:0724 | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | Third Party Advisory |
| access.redhat.com/errata/RHSA-2024:1278 | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | Third Party Advisory |
| access.redhat.com/errata/RHSA-2024:1367 | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | Third Party Advisory |
| net: tls, update curr on splice as well - kernel/git/torvalds/linux.git - Linux kernel source tree | af854a3a-2127-422b-91ae-364da2661108 | git.kernel.org | Patch |
| access.redhat.com/errata/RHSA-2024:0850 | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | Third Party Advisory |
| access.redhat.com/errata/RHSA-2024:1382 | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | Third Party Advisory |
| access.redhat.com/errata/RHSA-2024:1251 | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | Third Party Advisory |
| access.redhat.com/errata/RHSA-2024:1253 | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | Third Party Advisory |
| access.redhat.com/errata/RHSA-2024:0881 | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | Third Party Advisory |
| access.redhat.com/errata/RHSA-2024:1269 | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | Third Party Advisory |
| cve-details | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Additional Advisory Data
| Source | Time | Event |
|---|---|---|
| CNA | 2024-01-17T00:00:00.000Z | Reported to Red Hat. |
| CNA | 2023-12-07T06:30:00.000Z | Made public. |
Workarounds
CNA: To mitigate this issue, prevent module tls from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically.
Legacy QID Mappings
- 161372 Oracle Enterprise Linux Security Update for kernel (ELSA-2024-12169)
- 161402 Oracle Enterprise Linux Security Update for kernel (ELSA-2024-0897)
- 161417 Oracle Enterprise Linux Security Update for kernel (ELSA-2024-1248)
- 200116 Ubuntu Security Notification for Linux kernel (OEM) Vulnerabilities (USN-6639-1)
- 200131 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6648-1)
- 200132 Ubuntu Security Notification for Linux kernel (Azure) Vulnerabilities (USN-6652-1)
- 200133 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6653-1)
- 200134 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6651-1)
- 200150 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6651-2)
- 200151 Ubuntu Security Notification for Linux kernel (Azure) Vulnerabilities (USN-6648-2)
- 200152 Ubuntu Security Notification for Linux kernel (AWS) Vulnerabilities (USN-6653-2)
- 200157 Ubuntu Security Notification for Linux kernel (StarFive) Vulnerabilities (USN-6651-3)
- 200158 Ubuntu Security Notification for Linux kernel (Low Latency) Vulnerabilities (USN-6653-3)
- 200165 Ubuntu Security Notification for Linux kernel (GKE) Vulnerabilities (USN-6653-4)
- 242887 Red Hat Update for kernel-rt (RHSA-2024:0725)
- 242890 Red Hat Update for kernel (RHSA-2024:0724)
- 242908 Red Hat Update for kernel (RHSA-2024:0723)
- 242930 Red Hat Update for kpatch-patch (RHSA-2024:0850)
- 242931 Red Hat Update for kpatch-patch (RHSA-2024:0851)
- 242938 Red Hat Update for kpatch-patch (RHSA-2024:0876)
- 242939 Red Hat Update for kernel (RHSA-2024:0897)
- 242983 Red Hat Update for kernel-rt (RHSA-2024:0881)
- 243050 Red Hat Update for kernel (RHSA-2024:1250)
- 243052 Red Hat Update for kernel (RHSA-2024:1248)
- 243053 Red Hat Update for kernel live patch module (RHSA-2024:1253)
- 243054 Red Hat Update for kpatch-patch (RHSA-2024:1251)
- 243055 Red Hat Update for kernel (RHSA-2024:1268)
- 243057 Red Hat Update for kpatch-patch (RHSA-2024:1278)
- 243058 Red Hat Update for kernel-rt (RHSA-2024:1269)
- 243062 Red Hat Update for kernel-rt (RHSA-2024:1306)
- 243076 Red Hat Update for kernel (RHSA-2024:1367)
- 243078 Red Hat Update for kpatch-patch (RHSA-2024:1368)
- 243085 Red Hat Update for kpatch-patch (RHSA-2024:1377)
- 243087 Red Hat Update for kernel (RHSA-2024:1404)
- 243096 Red Hat Update for kernel-rt (RHSA-2024:1382)
- 357101 Amazon Linux Security Advisory for kernel : ALAS2KERNEL-5.10-2024-048
- 357105 Amazon Linux Security Advisory for kernel : ALAS2KERNEL-5.15-2024-036
- 357112 Amazon Linux Security Advisory for kernel : ALAS2KERNEL-5.4-2024-059
- 357311 Amazon Linux Security Advisory for kernel-livepatch : ALAS2LIVEPATCH-2024-166
- 357314 Amazon Linux Security Advisory for kernel-livepatch : ALAS2LIVEPATCH-2024-167
- 357318 Amazon Linux Security Advisory for kernel-livepatch : ALAS2LIVEPATCH-2024-169
- 6140032 AWS Bottlerocket Security Update for kernel (GHSA-vp24-6cwh-5x5c)
- 941584 AlmaLinux Security Update for kernel (ALSA-2024:0897)