An out-of-bounds memory write flaw was found in the Linux kernel’s Transport Layer Security functionality in how a user calls a function splice with a ktls socket as the destination. This flaw allows a local user to crash or potentially escalate their privileges on the system.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
19 Mar 2024, 23:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
19 Mar 2024, 17:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
19 Mar 2024, 05:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
13 Mar 2024, 15:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
12 Mar 2024, 21:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
12 Mar 2024, 15:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
12 Mar 2024, 04:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
20 Feb 2024, 15:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
07 Feb 2024, 21:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
24 Jan 2024, 21:04
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.8 |
| First Time |
Redhat enterprise Linux
Redhat Linux linux Kernel Linux |
|
| CWE | CWE-787 | |
| References | () https://access.redhat.com/security/cve/CVE-2024-0646 - Third Party Advisory | |
| References | () https://bugzilla.redhat.com/show_bug.cgi?id=2253908 - Issue Tracking, Patch | |
| References | () https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=c5a595000e267 - Patch | |
| CPE | cpe:2.3:o:linux:linux_kernel:6.7:rc2:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:6.7:rc1:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:6.7:rc4:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:6.7:rc3:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
17 Jan 2024, 17:35
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2024-01-17 16:15
Updated : 2024-03-19 23:15
NVD link : CVE-2024-0646
Mitre link : CVE-2024-0646
CVE.ORG link : CVE-2024-0646
JSON object : View
Products Affected
redhat
- enterprise_linux
linux
- linux_kernel
CWE
CWE-787
Out-of-bounds Write
