cbcvebase.
CVE-2024-35869
published 2024-05-19

CVE-2024-35869: In the Linux kernel, the following vulnerability has been resolved: smb: client: guarantee refcounted children from parent session Avoid potential…

PriorityP339high8.4CVSS 3.1
AVLACLPRNUINSUCHIHAH
EPSS
0.25%
16.8th percentile
In the Linux kernel, the following vulnerability has been resolved: smb: client: guarantee refcounted children from parent session Avoid potential use-after-free bugs when walking DFS referrals, mounting and performing DFS failover by ensuring that all children from parent @tcon->ses are also refcounted. They're all needed across the entire DFS mount. Get rid of @tcon->dfs_ses_list while we're at it, too.

Affected

17 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.8.9-1 (forky)linux 6.8.9-1 (forky)
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 6.2.15 < 6.36.3
linuxlinux>= 6.3.2 < 6.46.4
linuxlinux>= 8e3554150d6c80a84b3cb046615d1a0e943811dc < 645f332c6b63499cc76197f9b6bffcc659ba64cc645f332c6b63499cc76197f9b6bffcc659ba64cc
linuxlinux>= 8e3554150d6c80a84b3cb046615d1a0e943811dc < e1db9ae87b7148c021daee1fcc4bc71b2ac58a79e1db9ae87b7148c021daee1fcc4bc71b2ac58a79
linuxlinux>= 8e3554150d6c80a84b3cb046615d1a0e943811dc < 062a7f0ff46eb57aff526897bd2bebfdb1d3046a062a7f0ff46eb57aff526897bd2bebfdb1d3046a
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.8.9-16.8.9-1
linuxlinux_kernel>= 0 < 6.8.9-16.8.9-1
linuxlinux_kernel>= 0 < 6.8.0-38.386.8.0-38.38
linuxlinux_kernel>= 6.2.8 < 6.36.3
linuxlinux_kernel>= 6.4 < 6.6.296.6.29
linuxlinux_kernel>= 6.7 < 6.8.56.8.5
msrccbl2_kernel_5.15.182.1-1_on_cbl_mariner_2.0

CVSS provenance

nvdv3.18.4HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv8.4HIGH
vendor_debian8.4LOW
vendor_msrc8.4HIGH
vendor_redhat8.4HIGH
vendor_ubuntu4.6MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.