CVE-2024-26582 Information

Description

In the Linux kernel the following vulnerability has been resolved:

net: tls: fix use-after-free with partial reads and async decrypt

tls_decrypt_sg doesn’t take a reference on the pages from clear_skb so the put_page() in tls_decrypt_done releases them and we trigger a use-after-free in process_rx_list when we try to read from the partially-read skb.

Reference

https://git.kernel.org/stable/c/32b55c5ff9103b8508c1e04bfa5a08c64e7a925f

Share on: