Home

Description

In the Linux kernel, the following vulnerability has been resolved: tls: stop recv() if initial process_rx_list gave us non-DATA If we have a non-DATA record on the rx_list and another record of the same type still on the queue, we will end up merging them: - process_rx_list copies the non-DATA record - we start the loop and process the first available record since it's of the same type - we break out of the loop since the record was not DATA Just check the record type and jump to the end in case process_rx_list did some work.

PUBLISHED Reserved 2025-04-16 | Published 2025-08-22 | Updated 2025-08-22 | Assigner Linux

Product status

Default status
unaffected

692d7b5d1f9125a1cf0595e979e3b5fb7210547e before f310143961e2d9a0479fca117ce869f8aaecc140
affected

692d7b5d1f9125a1cf0595e979e3b5fb7210547e before 31e10d6cb0c9532ff070cf50da1657c3acee9276
affected

692d7b5d1f9125a1cf0595e979e3b5fb7210547e before 4338032aa90bd1d5b33a4274e8fa8347cda5ee09
affected

692d7b5d1f9125a1cf0595e979e3b5fb7210547e before 6756168add1c6c3ef1c32c335bb843a5d1f99a75
affected

692d7b5d1f9125a1cf0595e979e3b5fb7210547e before 3b952d8fdfcf6fd8ea0b8954bc9277642cf0977f
affected

692d7b5d1f9125a1cf0595e979e3b5fb7210547e before a4ed943882a8fc057ea5a67643314245e048bbdd
affected

692d7b5d1f9125a1cf0595e979e3b5fb7210547e before fdfbaec5923d9359698cbb286bc0deadbb717504
affected

Default status
affected

5.1
affected

Any version before 5.1
unaffected

5.4.270
unaffected

5.10.211
unaffected

5.15.150
unaffected

6.1.80
unaffected

6.6.19
unaffected

6.7.7
unaffected

6.8
unaffected

References

git.kernel.org/...c/f310143961e2d9a0479fca117ce869f8aaecc140

git.kernel.org/...c/31e10d6cb0c9532ff070cf50da1657c3acee9276

git.kernel.org/...c/4338032aa90bd1d5b33a4274e8fa8347cda5ee09

git.kernel.org/...c/6756168add1c6c3ef1c32c335bb843a5d1f99a75

git.kernel.org/...c/3b952d8fdfcf6fd8ea0b8954bc9277642cf0977f

git.kernel.org/...c/a4ed943882a8fc057ea5a67643314245e048bbdd

git.kernel.org/...c/fdfbaec5923d9359698cbb286bc0deadbb717504

cve.org (CVE-2024-58239)

nvd.nist.gov (CVE-2024-58239)

Download JSON