CVE-2024-26800

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Apr 4, 2024
Updated: Dec 20, 2024
CWE ID 416

Summary

CVE-2024-26800 is a vulnerability affecting the Linux kernel's Transport Layer Security (TLS) module. This issue arises when the TLS decryption process fails with the error code -EBUSY. In such cases, the Linux kernel assumes that all asynchronous decryptions have completed and releases the corresponding pages. However, these pages have already been passed to the async callback, leading to a use-after-free condition. This vulnerability can result in memory corruption and potential security exploits. The issue has been resolved by properly notifying the TLS decryption subsystem when memory has been released during asynchronous decryption.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share