CVE-2024-26585

tls: fix race between tx work scheduling and socket close

References

Notes

 carnil> Introduced in a42055e8d2c3 ("net/tls: Add support for async encryption of
 carnil> records for performance"). Vulnerable versions: 4.20-rc1.

Bugs

Status

Branch Status
upstream released (6.8-rc5) [e01e3934a1b2d122919f73bc6ddbe1cdafc4bbdb]
6.18-upstream-stable N/A "Fixed before branching point"
6.17-upstream-stable N/A "Fixed before branching point"
6.12-upstream-stable N/A "Fixed before branching point"
6.7-upstream-stable released (6.7.6) [e327ed60bff4a991cd7a709c47c4f0c5b4a4fd57]
6.6-upstream-stable released (6.6.18) [6db22d6c7a6dc914b12c0469b94eb639b6a8a146]
6.1-upstream-stable released (6.1.84) [196f198ca6fce04ba6ce262f5a0e4d567d7d219d]
5.10-upstream-stable needed
4.19-upstream-stable N/A "Vulnerable code not present"
sid released (6.7.7-1)
6.12-trixie-security N/A "Fixed before branching point"
6.1-bookworm-security released (6.1.85-1)
5.10-bullseye-security needed
4.19-buster-security N/A "Vulnerable code not present"