Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Vulnerabilities CVE-2024-0646

CVE-2024-0646

High
Open
TLP:CLEAR

Kernel: ktls overwrites readonly memory pages when using function splice with a ktls socket as destination

AI Analysis

No AI analysis yet.

Description

An out-of-bounds memory write flaw was found in the Linux kernel’s Transport Layer Security functionality in how a user calls a function splice with a ktls socket as the destination. This flaw allows a local user to crash or potentially escalate their privileges on the system.

Details

CVSS Score
7.0
EPSS Score
0.31%

23.5th percentile

CVSS Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Confidence
90%
Published
Jan 17, 2024
Last Modified
Aug 6, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.