We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2024-50086

ksmbd: fix user-after-free from session log off



Description

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix user-after-free from session log off There is racy issue between smb2 session log off and smb2 session setup. It will cause user-after-free from session log off. This add session_lock when setting SMB2_SESSION_EXPIRED and referece count to session struct not to free session while it is being used.

Reserved 2024-10-21 | Published 2024-10-29 | Updated 2025-05-04 | Assigner Linux

Product status

Default status
unaffected

0626e6641f6b467447c81dd7678a69c66f7746cf before 0f62358ce85b2d4c949ef1b648be01b29cec667a
affected

0626e6641f6b467447c81dd7678a69c66f7746cf before a9839c37fd813b432988f58a9d9dd59253d3eb2c
affected

0626e6641f6b467447c81dd7678a69c66f7746cf before 5511999e9615e4318e9142d23b29bd1597befc08
affected

0626e6641f6b467447c81dd7678a69c66f7746cf before ee371898b53a9b9b51c02d22a8c31bfb86d45f0d
affected

0626e6641f6b467447c81dd7678a69c66f7746cf before 7aa8804c0b67b3cb263a472d17f2cb50d7f1a930
affected

Default status
affected

5.15
affected

Any version before 5.15
unaffected

5.15.171
unaffected

6.1.114
unaffected

6.6.58
unaffected

6.11.5
unaffected

6.12
unaffected

References

git.kernel.org/...c/0f62358ce85b2d4c949ef1b648be01b29cec667a

git.kernel.org/...c/a9839c37fd813b432988f58a9d9dd59253d3eb2c

git.kernel.org/...c/5511999e9615e4318e9142d23b29bd1597befc08

git.kernel.org/...c/ee371898b53a9b9b51c02d22a8c31bfb86d45f0d

git.kernel.org/...c/7aa8804c0b67b3cb263a472d17f2cb50d7f1a930

cve.org (CVE-2024-50086)

nvd.nist.gov (CVE-2024-50086)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2024-50086

Support options

Helpdesk Chat, Email, Knowledgebase