tls: fix race between tx work scheduling and socket close
Summary
| CVE | CVE-2024-26585 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2024-02-21 15:15:09 UTC |
| Updated | 2026-08-04 11:16:45 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: tls: fix race between tx work scheduling and socket close Similarly to previous commit, the submitting thread (recvmsg/sendmsg) may exit as soon as the async crypto handler calls complete(). Reorder scheduling the work before calling complete(). This seems more logical in the first place, as it's the inverse order of what the submitting thread will do. |
Risk And Classification
Primary CVSS: v3.1 4.7 MEDIUM from [email protected]
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
Problem Types: CWE-362
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 4.7 | MEDIUM | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H |
| 3.1 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | Secondary | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | CNA | DECLARED | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
CVSS v3.1 Breakdown
Attack Vector
LocalAttack Complexity
HighPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
NoneIntegrity
NoneAvailability
HighCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Linux | Linux Kernel | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected a42055e8d2c30d4decfc13ce943d09c7b9dad221 dd32621f19243f89ce830919496a5dcc2158aa33 git | Not specified |
| CNA | Linux | Linux | affected a42055e8d2c30d4decfc13ce943d09c7b9dad221 196f198ca6fce04ba6ce262f5a0e4d567d7d219d git | Not specified |
| CNA | Linux | Linux | affected a42055e8d2c30d4decfc13ce943d09c7b9dad221 6db22d6c7a6dc914b12c0469b94eb639b6a8a146 git | Not specified |
| CNA | Linux | Linux | affected a42055e8d2c30d4decfc13ce943d09c7b9dad221 e327ed60bff4a991cd7a709c47c4f0c5b4a4fd57 git | Not specified |
| CNA | Linux | Linux | affected a42055e8d2c30d4decfc13ce943d09c7b9dad221 e01e3934a1b2d122919f73bc6ddbe1cdafc4bbdb git | Not specified |
| CNA | Linux | Linux | affected 4.20 | Not specified |
| CNA | Linux | Linux | unaffected 4.20 semver | Not specified |
| CNA | Linux | Linux | unaffected 5.15.165 5.15.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.1.84 6.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.6.18 6.6.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.7.6 6.7.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.8 * original_commit_for_fix | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/dd32621f19243f89ce830919496a5dcc2158aa33 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/196f198ca6fce04ba6ce262f5a0e4d567d7d219d | af854a3a-2127-422b-91ae-364da2661108 | git.kernel.org | |
| tls: fix race between tx work scheduling and socket close - kernel/git/stable/linux.git - Linux kernel stable tree | af854a3a-2127-422b-91ae-364da2661108 | git.kernel.org | Patch |
| tls: fix race between tx work scheduling and socket close - kernel/git/stable/linux.git - Linux kernel stable tree | af854a3a-2127-422b-91ae-364da2661108 | git.kernel.org | Patch |
| lists.fedoraproject.org/archives/list/[email protected]/messag... | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| tls: fix race between tx work scheduling and socket close - kernel/git/stable/linux.git - Linux kernel stable tree | af854a3a-2127-422b-91ae-364da2661108 | git.kernel.org | Patch |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 284941 Fedora Security Update for kernel (FEDORA-2024-71f0f16533)
- 284956 Fedora Security Update for kernel (FEDORA-2024-d16d94b00d)
- 6000567 Debian Security Update for linux (DSA 5658-1)
- 674156 EulerOS Security Update for kernel (EulerOS-SA-2024-1509)
- 755965 SUSE Enterprise Linux Security Update for the linux kernel (SUSE-SU-2024:0858-1)
- 755966 SUSE Enterprise Linux Security Update for the linux kernel (SUSE-SU-2024:0857-1)
- 755988 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2024:0975-1)
- 756004 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2024:0926-1)
- 756005 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2024:0925-1)
- 756010 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2024:0977-1)