CVE-2024-26585
tls: fix race between tx work scheduling and socket close
In the Linux kernel, the following vulnerability has been resolved:
tls: fix race between tx work scheduling and socket close
Similarly to previous commit, the submitting thread (recvmsg/sendmsg)
may exit as soon as the async crypto handler calls complete().
Reorder scheduling the work before calling complete().
This seems more logical in the first place, as it's
the inverse order of what the submitting thread will do.
Produtos afetados
Linux · LinuxQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
https://git.kernel.org/stable/c/196f198ca6fce04ba6ce262f5a0e4d567d7d219dhttps://git.kernel.org/stable/c/6db22d6c7a6dc914b12c0469b94eb639b6a8a146https://git.kernel.org/stable/c/dd32621f19243f89ce830919496a5dcc2158aa33https://git.kernel.org/stable/c/e01e3934a1b2d122919f73bc6ddbe1cdafc4bbdbhttps://git.kernel.org/stable/c/e327ed60bff4a991cd7a709c47c4f0c5b4a4fd57https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EZOU3745CWCDZ7EMKMXB2OEEIB5Q3IWM/