CVE-2024-0646
CVSS 3.1 Score 7.8 of 10 (high)
Details
Published Jan 17, 2024
Updated: Jul 8, 2024
CWE ID 787
Summary
CVE-2024-0646 is a newly discovered vulnerability affecting the Linux kernel's Transport Layer Security (TLS) functionality. This issue arises when a user utilizes the 'splice' function with a ktls socket as the destination. The out-of-bounds memory write flaw in this process can lead to system crashes, potentially enabling a local user to escalate their privileges. This vulnerability poses a significant security risk and requires immediate attention from system administrators to apply the necessary patches.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share