CVE-2024-58239

Analyzed
Published: 22 Aug 2025, 13:01
Last modified:11 May 2026, 21:03

Vulnerability Summary

Overall Risk (default)
low
22/100
CVSS Score
5.5 MEDIUM
v3.1 (nvd)
EPSS Score
<0.01% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

22 Aug 2025, 13:01
Published
Vulnerability first disclosed
11 May 2026, 21:03
Last Modified
Vulnerability information updated

Description

In the Linux kernel, the following vulnerability has been resolved: tls: stop recv() if initial process_rx_list gave us non-DATA If we have a non-DATA record on the rx_list and another record of the same type still on the queue, we will end up merging them: - process_rx_list copies the non-DATA record - we start the loop and process the first available record since it's of the same type - we break out of the loop since the record was not DATA Just check the record type and jump to the end in case process_rx_list did some work.

CVSS Metrics

  • v3.1MEDIUMScore: 5.5CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

EPSS Trends

Current EPSS score: 0.01% Percentile: 1%

Affected Systems

  • linuxlinux

    ≥ 692d7b5d1f9125a1cf0595e979e3b5fb7210547e, < f310143961e2d9a0479fca117ce869f8aaecc140 | ≥ 692d7b5d1f9125a1cf0595e979e3b5fb7210547e, < 31e10d6cb0c9532ff070cf50da1657c3acee9276 | ≥ 692d7b5d1f9125a1cf0595e979e3b5fb7210547e, < 4338032aa90bd1d5b33a4274e8fa8347cda5ee09 | ≥ 692d7b5d1f9125a1cf0595e979e3b5fb7210547e, < 6756168add1c6c3ef1c32c335bb843a5d1f99a75 | ≥ 692d7b5d1f9125a1cf0595e979e3b5fb7210547e, < 3b952d8fdfcf6fd8ea0b8954bc9277642cf0977f | ≥ 692d7b5d1f9125a1cf0595e979e3b5fb7210547e, < a4ed943882a8fc057ea5a67643314245e048bbdd | ≥ 692d7b5d1f9125a1cf0595e979e3b5fb7210547e, < fdfbaec5923d9359698cbb286bc0deadbb717504 | 5.1

  • linuxlinux_kernel

    ≥ 5.1, < 5.4.270 | ≥ 5.5, < 5.10.211 | ≥ 5.11, < 5.15.150 | ≥ 5.16, < 6.1.80 | ≥ 6.2, < 6.6.19 | ≥ 6.7, < 6.7.7 | 6.8:rc1 | 6.8:rc2 | 6.8:rc3 | 6.8:rc4 | 6.8:rc5

References (7)