cbcvebase.
CVE-2024-46736
published 2024-09-18

CVE-2024-46736: In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double put of @cfile in smb2_rename_path() If smb2_set_path_attr() is…

PriorityP335high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.24%
15.8th percentile
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double put of @cfile in smb2_rename_path() If smb2_set_path_attr() is called with a valid @cfile and returned -EINVAL, we need to call cifs_get_writable_path() again as the reference of @cfile was already dropped by previous smb2_compound_op() call.

Affected

11 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.10.11-1 (forky)linux 6.10.11-1 (forky)
linuxlinux
linuxlinux>= 1e60bc0e954389af82f1d9a85f13a63f6572350f < b27ea9c96efd2c252a981fb00d0f001b86c90f3eb27ea9c96efd2c252a981fb00d0f001b86c90f3e
linuxlinux>= 6.6.32 < 6.6.516.6.51
linuxlinux>= 71f15c90e785d1de4bcd65a279e7256684c25c0d < 1a46c7f6546b73cbf36f5a618a1a6bbb45391eb31a46c7f6546b73cbf36f5a618a1a6bbb45391eb3
linuxlinux>= 71f15c90e785d1de4bcd65a279e7256684c25c0d < 3523a3df03c6f04f7ea9c2e7050102657e331a4f3523a3df03c6f04f7ea9c2e7050102657e331a4f
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.10.11-16.10.11-1
linuxlinux_kernel>= 0 < 6.10.11-16.10.11-1
linuxlinux_kernel>= 6.6.32 < 6.6.516.6.51
linuxlinux_kernel>= 6.9 < 6.10.106.10.10

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8LOW
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.