Answer in brief
CVE-2024-26584 records a Unknown severity vulnerability in net: tls: handle backlogging of crypto requests. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2024-26584 records a Unknown severity vulnerability in net: tls: handle backlogging of crypto requests. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=a54667f6728c2714a400f3c884727da74b6d1717 <3ade391adc584f17b5570fd205de3ad029090368 || >=a54667f6728c2714a400f3c884727da74b6d1717 <cd1bbca03f3c1d845ce274c0d0a66de8e5929f72 || >=a54667f6728c2714a400f3c884727da74b6d1717 <13eca403876bbea3716e82cdfe6f1e6febb38754 || >=a54667f6728c2714a400f3c884727da74b6d1717 <ab6397f072e5097f267abf5cb08a8004e6b17694 || >=a54667f6728c2714a400f3c884727da74b6d1717 <8590541473188741055d27b955db0777569438e3 | 3ade391adc584f17b5570fd205de3ad029090368, cd1bbca03f3c1d845ce274c0d0a66de8e5929f72, 13eca403876bbea3716e82cdfe6f1e6febb38754, ab6397f072e5097f267abf5cb08a8004e6b17694, 8590541473188741055d27b955db0777569438e3 |
| Linux/Linuxgeneric | 4.16 | Not reported |
Published upstream
Feb 21, 2024
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: net: tls: handle backlogging of crypto requests Since we're setting the CRYPTO_TFM_REQ_MAY_BACKLOG flag on our requests to the crypto API, crypto_aead_{encrypt,decrypt} can return -EBUSY instead of -EINPROGRESS in valid situations. For example, when the cryptd queue for AESNI is full (easy to trigger with an artificially low cryptd.cryptd_max_cpu_qlen), requests will be enqueued to the backlog but still processed. In that case, the async callback will also be called twice: first with err == -EINPROGRESS, which it seems we can just ignore, then with err == 0. Compared to Sabrina's original patch this version uses the new tls_*crypt_async_wait() helpers and converts the EBUSY to EINPROGRESS to avoid having to modify all the error handling paths. The handling is identical.
Quoted source text, attributed separately from HOL analysis.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=a54667f6728c2714a400f3c884727da74b6d1717 <3ade391adc584f17b5570fd205de3ad029090368 || >=a54667f6728c2714a400f3c884727da74b6d1717 <cd1bbca03f3c1d845ce274c0d0a66de8e5929f72 || >=a54667f6728c2714a400f3c884727da74b6d1717 <13eca403876bbea3716e82cdfe6f1e6febb38754 || >=a54667f6728c2714a400f3c884727da74b6d1717 <ab6397f072e5097f267abf5cb08a8004e6b17694 || >=a54667f6728c2714a400f3c884727da74b6d1717 <8590541473188741055d27b955db0777569438e3 | 3ade391adc584f17b5570fd205de3ad029090368, cd1bbca03f3c1d845ce274c0d0a66de8e5929f72, 13eca403876bbea3716e82cdfe6f1e6febb38754, ab6397f072e5097f267abf5cb08a8004e6b17694, 8590541473188741055d27b955db0777569438e3 |
| Linux/Linuxgeneric | 4.16 | Not reported |
Published upstream
Feb 21, 2024
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: net: tls: handle backlogging of crypto requests Since we're setting the CRYPTO_TFM_REQ_MAY_BACKLOG flag on our requests to the crypto API, crypto_aead_{encrypt,decrypt} can return -EBUSY instead of -EINPROGRESS in valid situations. For example, when the cryptd queue for AESNI is full (easy to trigger with an artificially low cryptd.cryptd_max_cpu_qlen), requests will be enqueued to the backlog but still processed. In that case, the async callback will also be called twice: first with err == -EINPROGRESS, which it seems we can just ignore, then with err == 0. Compared to Sabrina's original patch this version uses the new tls_*crypt_async_wait() helpers and converts the EBUSY to EINPROGRESS to avoid having to modify all the error handling paths. The handling is identical.
Quoted source text, attributed separately from HOL analysis.