cbcvebase.
CVE-2024-42307
published 2024-08-17

CVE-2024-42307: In the Linux kernel, the following vulnerability has been resolved: cifs: fix potential null pointer use in destroy_workqueue in init_cifs error path Dan…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.21%
11.2th percentile
In the Linux kernel, the following vulnerability has been resolved: cifs: fix potential null pointer use in destroy_workqueue in init_cifs error path Dan Carpenter reported a Smack static checker warning: fs/smb/client/cifsfs.c:1981 init_cifs() error: we previously assumed 'serverclose_wq' could be null (see line 1895) The patch which introduced the serverclose workqueue used the wrong oredering in error paths in init_cifs() for freeing it on errors.

Affected

18 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.106-1 (bookworm)linux 6.1.106-1 (bookworm)
debianlinux-6.1< linux 6.1.106-1 (bookworm)linux 6.1.106-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux>= 173217bd73365867378b5e75a86f0049e1069ee8 < 3739d711246d8fbc95ff73dbdace9741cdce47773739d711246d8fbc95ff73dbdace9741cdce4777
linuxlinux>= 173217bd73365867378b5e75a86f0049e1069ee8 < 193cc89ea0ca1da311877d2b4bb5e9f03bcc82a2193cc89ea0ca1da311877d2b4bb5e9f03bcc82a2
linuxlinux>= 6.1.85 < 6.1.1036.1.103
linuxlinux>= 6.6.26 < 6.6.446.6.44
linuxlinux>= 6.8.5 < 6.96.9
linuxlinux>= 6f17163b9339fac92023a1d9bef22128db3b9a4b < 160235efb4f9b55212dedff5de0094c606c4b303160235efb4f9b55212dedff5de0094c606c4b303
linuxlinux>= 8c99dfb49bdc17edffc7ff3d46b400c8c291686c < 6018971710fdc7739f8655c1540832b4bb9036716018971710fdc7739f8655c1540832b4bb903671
linuxlinux_kernel>= 0 < 6.1.106-16.1.106-1
linuxlinux_kernel>= 0 < 6.10.3-16.10.3-1
linuxlinux_kernel>= 0 < 6.10.3-16.10.3-1
linuxlinux_kernel>= 0 < 6.8.0-50.516.8.0-50.51
linuxlinux_kernel>= 6.1.85 < 6.1.1036.1.103
linuxlinux_kernel>= 6.6.26 < 6.6.446.6.44
linuxlinux_kernel>= 6.8.5 < 6.10.36.10.3

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.