Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3841-1 | linux-5.10 security update |
EUVD |
EUVD-2024-16438 | An out-of-bounds memory write flaw was found in the Linux kernel’s Transport Layer Security functionality in how a user calls a function splice with a ktls socket as the destination. This flaw allows a local user to crash or potentially escalate their privileges on the system. |
Ubuntu USN |
USN-6639-1 | Linux kernel (OEM) vulnerabilities |
Ubuntu USN |
USN-6648-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-6648-2 | Linux kernel (Azure) vulnerabilities |
Ubuntu USN |
USN-6651-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-6651-2 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-6651-3 | Linux kernel (StarFive) vulnerabilities |
Ubuntu USN |
USN-6652-1 | Linux kernel (Azure) vulnerabilities |
Ubuntu USN |
USN-6653-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-6653-2 | Linux kernel (AWS) vulnerabilities |
Ubuntu USN |
USN-6653-3 | Linux kernel (Low Latency) vulnerabilities |
Ubuntu USN |
USN-6653-4 | Linux kernel (GKE) vulnerabilities |
Solution
No solution given by the vendor.
Workaround
To mitigate this issue, prevent module tls from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically.
Tue, 17 Jun 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 25 Nov 2024 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-1314 |
Fri, 22 Nov 2024 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 16 Oct 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-1314 |
Sat, 14 Sep 2024 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2025-11-06T20:51:54.670Z
Reserved: 2024-01-17T13:11:12.669Z
Link: CVE-2024-0646
Updated: 2024-08-01T18:11:35.718Z
Status : Modified
Published: 2024-01-17T16:15:47.190
Modified: 2024-11-25T10:44:03.660
Link: CVE-2024-0646
OpenCVE Enrichment
No data.
Debian DLA
EUVD
Ubuntu USN