{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2024-26583",
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "state": "PUBLISHED",
        "assignerShortName": "Linux",
        "dateReserved": "2024-02-19T14:20:24.125Z",
        "datePublished": "2024-02-21T14:59:11.845Z",
        "dateUpdated": "2026-08-05T11:26:02.205Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
                "shortName": "Linux",
                "dateUpdated": "2026-08-05T11:26:02.205Z"
            },
            "descriptions": [
                {
                    "lang": "en",
                    "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ntls: fix race between async notify and socket close\n\nThe submitting thread (one which called recvmsg/sendmsg)\nmay exit as soon as the async crypto handler calls complete()\nso any code past that point risks touching already freed data.\n\nTry to avoid the locking and extra flags altogether.\nHave the main thread hold an extra reference, this way\nwe can depend solely on the atomic ref counter for\nsynchronization.\n\nDon't futz with reiniting the completion, either, we are now\ntightly controlling when completion fires."
                }
            ],
            "metrics": [
                {
                    "cvssV3_1": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL"
                    },
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "AV:N - The vulnerable path is kTLS record processing (`net/tls/tls_sw.c`); the RX-side race is driven by TLS records sent by the remote peer of a kTLS-offloaded socket (kTLS HTTPS servers, NVMe-TCP/TLS), which controls how many async decryptions are in flight and when the final completion fires. Per kernel scoring guidance, kTLS bugs triggered by remote peer data are Network.\nAC:L - The attacker controls both sides of the race — it supplies the data that triggers the async crypto completions and drives the socket teardown (locally via its own close(), remotely by ending the request/connection so the server closes) — and can retry across thousands of concurrent connections until the window is won.\nPR:N - There is no capability or authorization check anywhere in net/tls; a remote peer of a public kTLS server needs no credentials, and a local attacker needs only an ordinary unprivileged socket to set the TLS ULP and install keys.\nUI:N - No victim action is required; the socket close that closes the race is ordinary application behavior the attacker induces, not a user-performed operation.\nS:U - The corruption is confined to kernel slab memory within the same security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - The freed `tls_sw_context_rx`/`tls_sw_context_tx` comes from a generic kmalloc cache and can be reclaimed by attacker-controlled objects, so the use-after-free gives control over freed-object contents and can be leveraged for kernel memory disclosure.\nI:H - The callback performs writes into the freed object (`spin_unlock_bh`, `test_and_set_bit` on `tx_bitmask`) and queues a `delayed_work` residing in freed memory whose function pointer is later dereferenced, yielding heap corruption at known offsets and a control-flow hijack primitive.\nA:H - The use-after-free reliably produces slab corruption, oopses and panics, and the lost-wakeup half of the race can leave the submitting thread blocked forever in uninterruptible sleep holding the socket."
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "unaffected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "include/net/tls.h",
                        "net/tls/tls_sw.c"
                    ],
                    "versions": [
                        {
                            "version": "0cada33241d9de205522e3858b18e506ca5cce2c",
                            "lessThan": "f17d21ea73918ace8afb9c2d8e734dbf71c2c9d7",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "0cada33241d9de205522e3858b18e506ca5cce2c",
                            "lessThan": "7a3ca06d04d589deec81f56229a9a9d62352ce01",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "0cada33241d9de205522e3858b18e506ca5cce2c",
                            "lessThan": "86dc27ee36f558fe223dbdfbfcb6856247356f4a",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "0cada33241d9de205522e3858b18e506ca5cce2c",
                            "lessThan": "6209319b2efdd8524691187ee99c40637558fa33",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "0cada33241d9de205522e3858b18e506ca5cce2c",
                            "lessThan": "aec7961916f3f9e88766e2688992da6980f11b8d",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "cf4cc95a15f599560c7abd89095a7973a4b9cec3",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "9b81d43da15e56ed89f083f326561acdcaf549ce",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "5.4.44",
                            "lessThan": "5.5",
                            "status": "affected",
                            "versionType": "semver"
                        },
                        {
                            "version": "5.6.16",
                            "lessThan": "5.7",
                            "status": "affected",
                            "versionType": "semver"
                        }
                    ]
                },
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "affected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "include/net/tls.h",
                        "net/tls/tls_sw.c"
                    ],
                    "versions": [
                        {
                            "version": "5.7",
                            "status": "affected"
                        },
                        {
                            "version": "0",
                            "lessThan": "5.7",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "5.15.160",
                            "lessThanOrEqual": "5.15.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.1.79",
                            "lessThanOrEqual": "6.1.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.6.18",
                            "lessThanOrEqual": "6.6.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.7.6",
                            "lessThanOrEqual": "6.7.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.8",
                            "lessThanOrEqual": "*",
                            "status": "unaffected",
                            "versionType": "original_commit_for_fix"
                        }
                    ]
                }
            ],
            "cpeApplicability": [
                {
                    "nodes": [
                        {
                            "operator": "OR",
                            "negate": false,
                            "cpeMatch": [
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.7",
                                    "versionEndExcluding": "5.15.160"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.7",
                                    "versionEndExcluding": "6.1.79"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.7",
                                    "versionEndExcluding": "6.6.18"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.7",
                                    "versionEndExcluding": "6.7.6"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.7",
                                    "versionEndExcluding": "6.8"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.4.44"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.6.16"
                                }
                            ]
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://git.kernel.org/stable/c/f17d21ea73918ace8afb9c2d8e734dbf71c2c9d7"
                },
                {
                    "url": "https://git.kernel.org/stable/c/7a3ca06d04d589deec81f56229a9a9d62352ce01"
                },
                {
                    "url": "https://git.kernel.org/stable/c/86dc27ee36f558fe223dbdfbfcb6856247356f4a"
                },
                {
                    "url": "https://git.kernel.org/stable/c/6209319b2efdd8524691187ee99c40637558fa33"
                },
                {
                    "url": "https://git.kernel.org/stable/c/aec7961916f3f9e88766e2688992da6980f11b8d"
                }
            ],
            "title": "tls: fix race between async notify and socket close",
            "x_generator": {
                "engine": "bippy-1.2.0"
            }
        },
        "adp": [
            {
                "metrics": [
                    {
                        "other": {
                            "type": "ssvc",
                            "content": {
                                "id": "CVE-2024-26583",
                                "role": "CISA Coordinator",
                                "options": [
                                    {
                                        "Exploitation": "none"
                                    },
                                    {
                                        "Automatable": "no"
                                    },
                                    {
                                        "Technical Impact": "partial"
                                    }
                                ],
                                "version": "2.0.3",
                                "timestamp": "2024-02-22T16:41:40.480459Z"
                            }
                        }
                    }
                ],
                "title": "CISA ADP Vulnrichment",
                "providerMetadata": {
                    "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
                    "shortName": "CISA-ADP",
                    "dateUpdated": "2024-07-05T17:21:01.043Z"
                }
            },
            {
                "title": "CVE Program Container",
                "references": [
                    {
                        "url": "https://git.kernel.org/stable/c/f17d21ea73918ace8afb9c2d8e734dbf71c2c9d7",
                        "tags": [
                            "x_transferred"
                        ]
                    },
                    {
                        "url": "https://git.kernel.org/stable/c/7a3ca06d04d589deec81f56229a9a9d62352ce01",
                        "tags": [
                            "x_transferred"
                        ]
                    },
                    {
                        "url": "https://git.kernel.org/stable/c/86dc27ee36f558fe223dbdfbfcb6856247356f4a",
                        "tags": [
                            "x_transferred"
                        ]
                    },
                    {
                        "url": "https://git.kernel.org/stable/c/6209319b2efdd8524691187ee99c40637558fa33",
                        "tags": [
                            "x_transferred"
                        ]
                    },
                    {
                        "url": "https://git.kernel.org/stable/c/aec7961916f3f9e88766e2688992da6980f11b8d",
                        "tags": [
                            "x_transferred"
                        ]
                    },
                    {
                        "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EZOU3745CWCDZ7EMKMXB2OEEIB5Q3IWM/"
                    }
                ],
                "providerMetadata": {
                    "orgId": "af854a3a-2127-422b-91ae-364da2661108",
                    "shortName": "CVE",
                    "dateUpdated": "2025-11-04T18:29:46.349Z"
                }
            }
        ]
    }
}