Lucene search

K
redhatcveRedhat.comRH:CVE-2024-26923
HistoryApr 25, 2024 - 2:39 p.m.

CVE-2024-26923

2024-04-2514:39:14
redhat.com
access.redhat.com
11
cve-2024-26923
vulnerability
information security

5.5 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

13.0%

A flaw was found in the Linux kernel, where the management of inter-process communication uses AF_UNIX sockets. The issue arises from a race condition where a partially initialized socket with specific permissions carrying SCM_RIGHTS is improperly handled during garbage collection. This situation leads to an incorrect count of active sockets, potentially causing resources to remain unaccounted for and never released.

Mitigation

There are no known mitigations to this issue and updating to the latest Linux kernel version is recommended to address this vulnerability​.

5.5 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

13.0%