CVE-2024-0646

high
Published 2024-03-12 · Modified 2024-02-22
CVSS v3
CVSS v2
VIR risk
8.0

Description

An out-of-bounds memory write flaw was found in the Linux kernel’s Transport Layer Security functionality in how a user calls a function splice with a ktls socket as the destination. This flaw allows a local user to crash or potentially escalate their privileges on the system.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: alma — https://errata.almalinux.org/8/ALSA-2024-0897.html

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2255139

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2254054

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2254053

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2254052

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2253908

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2253614

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2253611

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2246945

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2246944

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2245514

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2244723

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2237757

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2231800

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2187931

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2187813

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2173403

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2161310

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2144379

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2087568

vendor Authored 2026-05-27

Vendor advisory: alma — https://access.redhat.com/errata/RHSA-2024:0897

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2024-0646

vendor Authored 2026-05-27

Vendor advisory: rocky — https://errata.rockylinux.org/RXSA-2024:1248

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2024-0646.html

vendor Authored 2026-05-27

Vendor advisory: redhat — https://access.redhat.com/errata/RHSA-2024:1251

vendor Authored 2026-05-27

Vendor advisory: redhat — https://access.redhat.com/errata/RHSA-2024:1248

OS impact

OSVersionStatusFixed in
redhat rhel9fixed
suse slesaffected
rockylinux rocky9fixed
debian debianbookwormfixed6.1.69-1
debian debianbullseyefixed5.10.209-1
debian debianforkyfixed6.6.8-1
debian debiansidfixed6.6.8-1
debian debiantrixiefixed6.6.8-1
almalinux almalinux8fixedkernel-doc-4.18.0-513.18.1.el8_9.noarch.rpm

References

Verify integrity in audit chain (admin only). AS-IS.