CVE-2024-58239: Linux Kernel
Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: tls: stop recv() if initial process_rx_list gave us non-DATA If we have a non-DATA record on the rx_list and another record of the same type still on the queue, we will end up merging them: - process_rx_list copies the non-DATA record - we start the loop and process the first available record since it's of the same type - we break out of the loop since the record was not DATA Just check the record type and jump to the end in case process_rx_list did some work.
Affected products
- Linux Linux Kernel: from 5.1, before 5.4.270 (fixed in 5.4.270); from 5.5, before 5.10.211 (fixed in 5.10.211); from 5.11, before 5.15.150 (fixed in 5.15.150); from 5.16, before 6.1.80 (fixed in 6.1.80); from 6.2, before 6.6.19 (fixed in 6.6.19); from 6.7, before 6.7.7 (fixed in 6.7.7); …
Published 2025-08-22. Last modified 2026-08-04.