---
id: CVE-2024-26583
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  tls: fix race between async notify and socket close

  The submitting thread (one which called recvmsg/sendmsg)
  may exit as soon as the async crypto handler calls complet…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  tls: fix race between async notify and socket close

  The submitting thread (one which called recvmsg/sendmsg)
  may exit as soon as the async crypto handler calls complet…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-362
vendor: linux
product: linux_kernel
affected:
  - 'linux_kernel >= 5.7.0, < 6.1.79'
  - 'linux_kernel >= 6.2.0, < 6.6.18'
  - 'linux_kernel >= 6.7.0, < 6.7.6'
patched:
  - linux_kernel 6.7.6
published: '2024-02-21'
updated: '2026-08-04'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-26583'
references:
  - url: 'https://git.kernel.org/stable/c/6209319b2efdd8524691187ee99c40637558fa33'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/7a3ca06d04d589deec81f56229a9a9d62352ce01'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/86dc27ee36f558fe223dbdfbfcb6856247356f4a'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/aec7961916f3f9e88766e2688992da6980f11b8d'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/f17d21ea73918ace8afb9c2d8e734dbf71c2c9d7'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/6209319b2efdd8524691187ee99c40637558fa33'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://git.kernel.org/stable/c/7a3ca06d04d589deec81f56229a9a9d62352ce01'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://git.kernel.org/stable/c/86dc27ee36f558fe223dbdfbfcb6856247356f4a'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://git.kernel.org/stable/c/aec7961916f3f9e88766e2688992da6980f11b8d'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://git.kernel.org/stable/c/f17d21ea73918ace8afb9c2d8e734dbf71c2c9d7'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EZOU3745CWCDZ7EMKMXB2OEEIB5Q3IWM/
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00546
epssPercentile: 0.43314
ingestedAt: '2026-08-04T11:39:45.137Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

tls: fix race between async notify and socket close

The submitting thread (one which called recvmsg/sendmsg)
may exit as soon as the async crypto handler calls complete()
so any code past that point risks touching already freed data.

Try to avoid the locking and extra flags altogether.
Have the main thread hold an extra reference, this way
we can depend solely on the atomic ref counter for
synchronization.

Don't futz with reiniting the completion, either, we are now
tightly controlling when completion fires.

## Affected

- `linux_kernel >= 5.7.0, < 6.1.79`
- `linux_kernel >= 6.2.0, < 6.6.18`
- `linux_kernel >= 6.7.0, < 6.7.6`

## Remediation

Upgrade past the affected range:

- `linux_kernel 6.7.6`
