CVE-2024-0646

Red Hat Security Advisory: kernel security and bug fix update

Description

An out-of-bounds memory write flaw was found in the Linux kernel’s Transport Layer Security functionality in how a user calls a function splice with a ktls socket as the destination. This flaw allows a local user to crash or potentially escalate their privileges on the system.

Source: redhat_csaf

Metrics

21.7 %
Elevated — this CVE ranks above at least 10% of all CVEs scored today.
Show all metrics
Severity
high
no public PoC known
0.3 %
Low — model estimates < 1% exploitation likelihood.
Published
2024-02-07 16:33 UTC

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. CVE Modified2026-08-06 22:16 UTC· secalert@redhat.com
    • Affected: …, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 8 (+46) → …, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 8 (+46)

Included in the same advisory

Show 32 more CVEs