tls: fix race between tx work scheduling and socket close
28Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 9.8epss 0.6%
probabilidad de explotación
0.6%top 55% de las CVE
explotación observada
noninguna fuente lo reporta
In the Linux kernel, the following vulnerability has been resolved:
tls: fix race between tx work scheduling and socket close
Similarly to previous commit, the submitting thread (recvmsg/sendmsg)
may exit as soon as the async crypto handler calls complete().
Reorder scheduling the work before calling complete().
This seems more logical in the first place, as it's
the inverse order of what the submitting thread will do.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Productos afectados
Linux · LinuxReferencias
https://git.kernel.org/stable/c/196f198ca6fce04ba6ce262f5a0e4d567d7d219dhttps://git.kernel.org/stable/c/6db22d6c7a6dc914b12c0469b94eb639b6a8a146https://git.kernel.org/stable/c/dd32621f19243f89ce830919496a5dcc2158aa33https://git.kernel.org/stable/c/e01e3934a1b2d122919f73bc6ddbe1cdafc4bbdbhttps://git.kernel.org/stable/c/e327ed60bff4a991cd7a709c47c4f0c5b4a4fd57https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EZOU3745CWCDZ7EMKMXB2OEEIB5Q3IWM/