CVE-2024-46736
published 2024-09-18CVE-2024-46736: In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double put of @cfile in smb2_rename_path() If smb2_set_path_attr() is…
PriorityP335high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.24%
15.8th percentile
In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix double put of @cfile in smb2_rename_path()
If smb2_set_path_attr() is called with a valid @cfile and returned
-EINVAL, we need to call cifs_get_writable_path() again as the
reference of @cfile was already dropped by previous smb2_compound_op()
call.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.10.11-1 (forky) | linux 6.10.11-1 (forky) |
| linux | linux | — | — |
| linux | linux | >= 1e60bc0e954389af82f1d9a85f13a63f6572350f < b27ea9c96efd2c252a981fb00d0f001b86c90f3e | b27ea9c96efd2c252a981fb00d0f001b86c90f3e |
| linux | linux | >= 6.6.32 < 6.6.51 | 6.6.51 |
| linux | linux | >= 71f15c90e785d1de4bcd65a279e7256684c25c0d < 1a46c7f6546b73cbf36f5a618a1a6bbb45391eb3 | 1a46c7f6546b73cbf36f5a618a1a6bbb45391eb3 |
| linux | linux | >= 71f15c90e785d1de4bcd65a279e7256684c25c0d < 3523a3df03c6f04f7ea9c2e7050102657e331a4f | 3523a3df03c6f04f7ea9c2e7050102657e331a4f |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 6.10.11-1 | 6.10.11-1 |
| linux | linux_kernel | >= 0 < 6.10.11-1 | 6.10.11-1 |
| linux | linux_kernel | >= 6.6.32 < 6.6.51 | 6.6.51 |
| linux | linux_kernel | >= 6.9 < 6.10.10 | 6.10.10 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8LOW
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: smb: client: fix double put of @cfile in smb2_rename_path()
vendor_redhat·2024-09-18·CVSS 7.8
CVE-2024-46736 [HIGH] CWE-404 kernel: smb: client: fix double put of @cfile in smb2_rename_path()
kernel: smb: client: fix double put of @cfile in smb2_rename_path()
In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix double put of @cfile in smb2_rename_path()
If smb2_set_path_attr() is called with a valid @cfile and returned
-EINVAL, we need to call cifs_get_writable_path() again as the
reference of @cfile was already dropped by previous smb2_compound_op()
call.
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel (Red Hat Enterprise Linux 8) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 8) - Not affected
Package: kernel (Red Hat Enterprise Linux 9) - Affected
Package: kernel-rt (Red Hat
Debian
CVE-2024-46736: linux - In the Linux kernel, the following vulnerability has been resolved: smb: client...
vendor_debian·2024·CVSS 7.8
CVE-2024-46736 [HIGH] CVE-2024-46736: linux - In the Linux kernel, the following vulnerability has been resolved: smb: client...
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double put of @cfile in smb2_rename_path() If smb2_set_path_attr() is called with a valid @cfile and returned -EINVAL, we need to call cifs_get_writable_path() again as the reference of @cfile was already dropped by previous smb2_compound_op() call.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 6.10.11-1)
sid: resolved (fixed in 6.10.11-1)
trixie: resolved (fixed in 6.10.11-1)
OSV
CVE-2024-46736: In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double put of @cfile in smb2_rename_path() If smb2_set_path_attr(
osv·2024-09-18·CVSS 7.8
CVE-2024-46736 [HIGH] CVE-2024-46736: In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double put of @cfile in smb2_rename_path() If smb2_set_path_attr(
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double put of @cfile in smb2_rename_path() If smb2_set_path_attr() is called with a valid @cfile and returned -EINVAL, we need to call cifs_get_writable_path() again as the reference of @cfile was already dropped by previous smb2_compound_op() call.
GHSA
GHSA-v7w6-282w-jqp8: In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix double put of @cfile in smb2_rename_path()
If smb2_set_path_att
ghsa_unreviewed·2024-09-18
CVE-2024-46736 [HIGH] CWE-415 GHSA-v7w6-282w-jqp8: In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix double put of @cfile in smb2_rename_path()
If smb2_set_path_att
In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix double put of @cfile in smb2_rename_path()
If smb2_set_path_attr() is called with a valid @cfile and returned
-EINVAL, we need to call cifs_get_writable_path() again as the
reference of @cfile was already dropped by previous smb2_compound_op()
call.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-09-18
Published