---
id: CVE-2024-26584
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  net: tls: handle backlogging of crypto requests

  Since we're setting the CRYPTO_TFM_REQ_MAY_BACKLOG flag on our
  requests to the crypto API, crypto_aead_{encrypt,decrypt…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  net: tls: handle backlogging of crypto requests

  Since we're setting the CRYPTO_TFM_REQ_MAY_BACKLOG flag on our
  requests to the crypto API, crypto_aead_{encrypt,decrypt…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-755
vendor: linux
product: linux_kernel
affected:
  - 'linux_kernel >= 4.16.0, < 6.1.84'
  - 'linux_kernel >= 6.2.0, < 6.6.18'
  - 'linux_kernel >= 6.7.0, < 6.7.6'
patched:
  - linux_kernel 6.7.6
published: '2024-02-21'
updated: '2026-08-04'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-26584'
references:
  - url: 'https://git.kernel.org/stable/c/13eca403876bbea3716e82cdfe6f1e6febb38754'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/3ade391adc584f17b5570fd205de3ad029090368'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/8590541473188741055d27b955db0777569438e3'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/ab6397f072e5097f267abf5cb08a8004e6b17694'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/cd1bbca03f3c1d845ce274c0d0a66de8e5929f72'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/13eca403876bbea3716e82cdfe6f1e6febb38754'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://git.kernel.org/stable/c/3ade391adc584f17b5570fd205de3ad029090368'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://git.kernel.org/stable/c/8590541473188741055d27b955db0777569438e3'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://git.kernel.org/stable/c/ab6397f072e5097f267abf5cb08a8004e6b17694'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://git.kernel.org/stable/c/cd1bbca03f3c1d845ce274c0d0a66de8e5929f72'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EZOU3745CWCDZ7EMKMXB2OEEIB5Q3IWM/
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00746
epssPercentile: 0.52866
ingestedAt: '2026-08-04T11:39:45.167Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

net: tls: handle backlogging of crypto requests

Since we're setting the CRYPTO_TFM_REQ_MAY_BACKLOG flag on our
requests to the crypto API, crypto_aead_{encrypt,decrypt} can return
 -EBUSY instead of -EINPROGRESS in valid situations. For example, when
the cryptd queue for AESNI is full (easy to trigger with an
artificially low cryptd.cryptd_max_cpu_qlen), requests will be enqueued
to the backlog but still processed. In that case, the async callback
will also be called twice: first with err == -EINPROGRESS, which it
seems we can just ignore, then with err == 0.

Compared to Sabrina's original patch this version uses the new
tls_*crypt_async_wait() helpers and converts the EBUSY to
EINPROGRESS to avoid having to modify all the error handling
paths. The handling is identical.

## Affected

- `linux_kernel >= 4.16.0, < 6.1.84`
- `linux_kernel >= 6.2.0, < 6.6.18`
- `linux_kernel >= 6.7.0, < 6.7.6`

## Remediation

Upgrade past the affected range:

- `linux_kernel 6.7.6`
