cbcvebase.
CVE-2024-26928
published 2024-04-28

CVE-2024-26928: In the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential UAF in cifs_debug_files_proc_show() Skip sessions that are being…

PriorityP336high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.28%
19.9th percentile
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential UAF in cifs_debug_files_proc_show() Skip sessions that are being teared down (status == SES_EXITING) to avoid UAF.

Affected

28 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.85-1 (bookworm)linux 6.1.85-1 (bookworm)
linuxlinux
linuxlinux>= dfe33f9abc08997e56f9bdf14fe9ac7ac0e14075 < 8f8718afd446cd4ea3b62bacc3eec09f8aae85ee8f8718afd446cd4ea3b62bacc3eec09f8aae85ee
linuxlinux>= dfe33f9abc08997e56f9bdf14fe9ac7ac0e14075 < a140224bcf87eb98a87b67ff4c6826c57e47b704a140224bcf87eb98a87b67ff4c6826c57e47b704
linuxlinux>= dfe33f9abc08997e56f9bdf14fe9ac7ac0e14075 < 229042314602db62559ecacba127067c22ee7b88229042314602db62559ecacba127067c22ee7b88
linuxlinux>= dfe33f9abc08997e56f9bdf14fe9ac7ac0e14075 < a65f2b56334ba4dc30bd5ee9ce5b2691b973344da65f2b56334ba4dc30bd5ee9ce5b2691b973344d
linuxlinux>= dfe33f9abc08997e56f9bdf14fe9ac7ac0e14075 < 3402faf78b2516b0af1259baff50cc8453ef0bd13402faf78b2516b0af1259baff50cc8453ef0bd1
linuxlinux>= dfe33f9abc08997e56f9bdf14fe9ac7ac0e14075 < ca545b7f0823f19db0f1148d59bc5e1a56634502ca545b7f0823f19db0f1148d59bc5e1a56634502
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.237-15.10.237-1
linuxlinux_kernel>= 0 < 6.1.85-16.1.85-1
linuxlinux_kernel>= 0 < 6.8.9-16.8.9-1
linuxlinux_kernel>= 0 < 6.8.9-16.8.9-1
linuxlinux_kernel>= 0 < 5.4.0-212.2325.4.0-212.232
linuxlinux_kernel>= 0 < 5.15.0-136.1475.15.0-136.147
linuxlinux_kernel>= 0 < 6.8.0-38.386.8.0-38.38
linuxlinux_kernel>= 0 < 4.15.0-237.2494.15.0-237.249
linuxlinux_kernel>= 0 < 5.4.0-212.2325.4.0-212.232
linuxlinux_kernel>= 0 < 5.15.0-138.1485.15.0-138.148
linuxlinux_kernel>= 0 < 6.8.0-57.596.8.0-57.59
linuxlinux_kernel>= 4.20 < 5.10.2375.10.237
linuxlinux_kernel>= 5.11 < 5.15.1805.15.180
linuxlinux_kernel>= 5.16 < 6.1.856.1.85
linuxlinux_kernel>= 6.2 < 6.6.266.6.26

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.