CVE-2024-0646
גבוהה 7.8
תיאור (מקור, אנגלית)
An out-of-bounds memory write flaw was found in the Linux kernel’s Transport Layer Security functionality in how a user calls a function splice with a ktls socket as the destination. This flaw allows a local user to crash or potentially escalate their privileges on the system.
מדדים
- CVSS 3.1
-
7.8 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 0% (אחוזון 000) נכון ל-17/9/2026
- CWE
- CWE-787
מוצרים מושפעים
linux: linux kernel; redhat: enterprise linux
קישורים
- https://bugzilla.redhat.com/show_bug.cgi?id=2253908 Issue TrackingPatch
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=… Patch
- https://bugzilla.redhat.com/show_bug.cgi?id=2253908 Issue TrackingPatch
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=… Patch
- https://access.redhat.com/errata/RHSA-2024:0723 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2024:0724 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2024:0725 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2024:0850 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2024:0851 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2024:0876 Third Party Advisory