Answer in brief
CVE-2024-26800 records a Unknown severity vulnerability in tls: fix use-after-free on failed backlog decryption. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=6.6.18 <6.6.21 || >=6.7.6 <6.7.9 | 6.6.21, 6.7.9 |
| Linux/Linuxgeneric | >=cd1bbca03f3c1d845ce274c0d0a66de8e5929f72 <f2b85a4cc763841843de693bbd7308fe9a2c4c89 || >=13eca403876bbea3716e82cdfe6f1e6febb38754 <81be85353b0f5a7b660635634b655329b429eefe || >=ab6397f072e5097f267abf5cb08a8004e6b17694 <1ac9fb84bc7ecd4bc6428118301d9d864d2a58d1 || >=8590541473188741055d27b955db0777569438e3 <13114dc5543069f7b97991e3b79937b6da05f5b0 || 3ade391adc584f17b5570fd205de3ad029090368 || >=5.15.160 <5.16 | f2b85a4cc763841843de693bbd7308fe9a2c4c89, 81be85353b0f5a7b660635634b655329b429eefe, 1ac9fb84bc7ecd4bc6428118301d9d864d2a58d1, 13114dc5543069f7b97991e3b79937b6da05f5b0, 5.16 |
Published upstream
Apr 4, 2024
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: tls: fix use-after-free on failed backlog decryption When the decrypt request goes to the backlog and crypto_aead_decrypt returns -EBUSY, tls_do_decryption will wait until all async decryptions have completed. If one of them fails, tls_do_decryption will return -EBADMSG and tls_decrypt_sg jumps to the error path, releasing all the pages. But the pages have been passed to the async callback, and have already been released by tls_decrypt_done. The only true async case is when crypto_aead_decrypt returns -EINPROGRESS. With -EBUSY, we already waited so we can tell tls_sw_recvmsg that the data is available for immediate copy, but we need to notify tls_decrypt_sg (via the new ->async_done flag) that the memory has already been released.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2024-26800 records a Unknown severity vulnerability in tls: fix use-after-free on failed backlog decryption. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=6.6.18 <6.6.21 || >=6.7.6 <6.7.9 | 6.6.21, 6.7.9 |
| Linux/Linuxgeneric | >=cd1bbca03f3c1d845ce274c0d0a66de8e5929f72 <f2b85a4cc763841843de693bbd7308fe9a2c4c89 || >=13eca403876bbea3716e82cdfe6f1e6febb38754 <81be85353b0f5a7b660635634b655329b429eefe || >=ab6397f072e5097f267abf5cb08a8004e6b17694 <1ac9fb84bc7ecd4bc6428118301d9d864d2a58d1 || >=8590541473188741055d27b955db0777569438e3 <13114dc5543069f7b97991e3b79937b6da05f5b0 || 3ade391adc584f17b5570fd205de3ad029090368 || >=5.15.160 <5.16 | f2b85a4cc763841843de693bbd7308fe9a2c4c89, 81be85353b0f5a7b660635634b655329b429eefe, 1ac9fb84bc7ecd4bc6428118301d9d864d2a58d1, 13114dc5543069f7b97991e3b79937b6da05f5b0, 5.16 |
Published upstream
Apr 4, 2024
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: tls: fix use-after-free on failed backlog decryption When the decrypt request goes to the backlog and crypto_aead_decrypt returns -EBUSY, tls_do_decryption will wait until all async decryptions have completed. If one of them fails, tls_do_decryption will return -EBADMSG and tls_decrypt_sg jumps to the error path, releasing all the pages. But the pages have been passed to the async callback, and have already been released by tls_decrypt_done. The only true async case is when crypto_aead_decrypt returns -EINPROGRESS. With -EBUSY, we already waited so we can tell tls_sw_recvmsg that the data is available for immediate copy, but we need to notify tls_decrypt_sg (via the new ->async_done flag) that the memory has already been released.
Quoted source text, attributed separately from HOL analysis.