CVE-2024-0646: High Fixes for in Linux Kernel

Published Dec 10, 2023
·
Updated

A flaw in the Linux Kernel found. When splice() is called with a ktls socket as destination, the ktls code fails to update the internal "curr"/"copybreak" accounting that tracks which parts of the plaintext scatter-gather buffer (struct skmsgsg) are unused writable memory. This can cause subsequent writes to the socket to overwrite the contents of spliced pages, including pages from files to which the caller is not supposed to have write access.

Reference: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=c5a595000e267

Other sources

An out-of-bounds memory write flaw was found in the Linux kernel’s Transport Layer Security functionality in how a user calls a function splice with a ktls socket as the destination. This flaw allows a local user to crash or potentially escalate their privileges on the system.

Launchpad

Kernel: ktls overwrites readonly memory pages when using function splice with a ktls socket as destination

Microsoft

Linux Kernel could allow a local authenticated attacker to gain elevated privileges on the system, caused by an out-of-bounds memory write flaw in the Transport Layer Security functionality. A local attacker could exploit this vulnerability to gain elevated privileges or cause the system to crash.

IBM

Affected Software

20 affected componentsFixes available
Linux Linux kernel>=4.20<5.4.267
Linux Linux kernel>=5.5<5.10.208
Linux Linux kernel>=5.11<5.15.147
Linux Linux kernel>=5.16<6.1.69
Linux Linux kernel>=6.2<6.6.7
Linux Linux kernel=6.7-rc1
Linux Linux kernel=6.7-rc2
Linux Linux kernel=6.7-rc3
Linux Linux kernel=6.7-rc4
redhat Enterprise Linux=8.0
redhat Enterprise Linux=9.0
IBM Security Verify Governance, Identity Manager software component<=ISVG 10.0.2
IBM Security Verify Governance, Identity Manager virtual appliance component<=ISVG 10.0.2
debian/linux
5.10.223-15.10.234-16.1.129-16.1.135-16.12.25-16.12.27-1
redhat/kernel<6.7
6.7
Microsoft azl3 kernel 6.6.35.1-4
Microsoft cbl2 kernel 5.15.153.1-1
Microsoft cbl2 kernel 5.15.164.1-1
Microsoft azl3 kernel 6.6.47.1-1
Microsoft cbl2 kernel 5.15.164.1-1

Event History

Dec 10, 2023
Data Sourced
via Red Hat·08:54 PM
DescriptionSeverityAffected Software
Jan 17, 2024
CVE Published
via MITRE·03:16 PM
Data Sourced
via MITRE·03:16 PM
DescriptionSeverityWeakness
Jan 26, 2024
Data Sourced
via Microsoft·08:00 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·08:00 AM
Affected Software
Updated
via Microsoft·08:00 AM
DescriptionSeverity
Mar 5, 2024
Data Sourced
12:00 AM
SeverityWeakness
Mar 30, 2024
Data Sourced
via Launchpad·04:45 AM
Description
Apr 26, 2025
Data Sourced
via Ubuntu·11:50 PM
RemedyDescriptionSeverityAffected Software

Parent advisories

This vulnerability appears in the following advisories.

Peer vulnerabilities

Found alongside the following vulnerabilities.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-0646?

CVE-2024-0646 is classified as a significant vulnerability in the Linux Kernel affecting ktls sockets.

2

What systems are affected by CVE-2024-0646?

CVE-2024-0646 affects various versions of the Linux Kernel, Red Hat Enterprise Linux, and specific IBM products.

3

How do I fix CVE-2024-0646?

To fix CVE-2024-0646, update your Linux Kernel to versions 6.7 or apply patches to vulnerable systems.

4

What is the impact of CVE-2024-0646?

CVE-2024-0646 may lead to improper access control on ktls sockets, potentially allowing unauthorized access to memory.

5

When was CVE-2024-0646 discovered?

CVE-2024-0646 was publicly disclosed in 2024.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203