CVE-2024-26585: Linux Kernel
Medium severity, CVSS 4.7. EPSS: 0.6% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: tls: fix race between tx work scheduling and socket close Similarly to previous commit, the submitting thread (recvmsg/sendmsg) may exit as soon as the async crypto handler calls complete(). Reorder scheduling the work before calling complete(). This seems more logical in the first place, as it's the inverse order of what the submitting thread will do.
Affected products
- Linux Linux Kernel: from 4.20.0, before 6.6.18 (fixed in 6.6.18); from 6.7.0, before 6.7.6 (fixed in 6.7.6)
Published 2024-02-21. Last modified 2026-08-04.