Database/Kernel, userspace & hypervisor
Linux kernel (kTLS): splice() into a kTLS socket overwrites read-only kernel pages - local privilege escalation
CVE-2024-0646Kernel, userspace & hypervisorcurated
Impact
splice() into a kTLS socket overwrites read-only kernel pages - local privilege escalation
Who can reach it
Any tenant process in a container
What to do
Livepatchable; otherwise drain + reboot
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.