CVE-2024-26594 — Out-of-bounds Read in Linux
Severity
7.1HIGHNVD
OSV7.5OSV6.5
EPSS
0.8%
top 25.40%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 23
Latest updateJun 26
Description
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: validate mech token in session setup
If client send invalid mech token in session setup request, ksmbd
validate and make the error if it is invalid.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:HExploitability: 1.8 | Impact: 5.2
Affected Packages9 packages
▶CVEListV5linux/linux0626e6641f6b467447c81dd7678a69c66f7746cf — dd1de9268745f0eac83a430db7afc32cbd62e84b+5