-

CVE-2024-58239

In the Linux kernel, the following vulnerability has been resolved:

tls: stop recv() if initial process_rx_list gave us non-DATA

If we have a non-DATA record on the rx_list and another record of the
same type still on the queue, we will end up merging them:
 - process_rx_list copies the non-DATA record
 - we start the loop and process the first available record since it's
   of the same type
 - we break out of the loop since the record was not DATA

Just check the record type and jump to the end in case process_rx_list
did some work.

Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
This information is available to logged-in users.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
VendorLinux
Product Linux
Default Statusunaffected
Version < f310143961e2d9a0479fca117ce869f8aaecc140
Version 692d7b5d1f9125a1cf0595e979e3b5fb7210547e
Status affected
Version < 31e10d6cb0c9532ff070cf50da1657c3acee9276
Version 692d7b5d1f9125a1cf0595e979e3b5fb7210547e
Status affected
Version < 4338032aa90bd1d5b33a4274e8fa8347cda5ee09
Version 692d7b5d1f9125a1cf0595e979e3b5fb7210547e
Status affected
Version < 6756168add1c6c3ef1c32c335bb843a5d1f99a75
Version 692d7b5d1f9125a1cf0595e979e3b5fb7210547e
Status affected
Version < 3b952d8fdfcf6fd8ea0b8954bc9277642cf0977f
Version 692d7b5d1f9125a1cf0595e979e3b5fb7210547e
Status affected
Version < a4ed943882a8fc057ea5a67643314245e048bbdd
Version 692d7b5d1f9125a1cf0595e979e3b5fb7210547e
Status affected
Version < fdfbaec5923d9359698cbb286bc0deadbb717504
Version 692d7b5d1f9125a1cf0595e979e3b5fb7210547e
Status affected
VendorLinux
Product Linux
Default Statusaffected
Version 5.1
Status affected
Version < 5.1
Version 0
Status unaffected
Version <= 5.4.*
Version 5.4.270
Status unaffected
Version <= 5.10.*
Version 5.10.211
Status unaffected
Version <= 5.15.*
Version 5.15.150
Status unaffected
Version <= 6.1.*
Version 6.1.80
Status unaffected
Version <= 6.6.*
Version 6.6.19
Status unaffected
Version <= 6.7.*
Version 6.7.7
Status unaffected
Version <= *
Version 6.8
Status unaffected
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.04% 0.089
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string