cbcvebase.
CVE-2024-46742
published 2024-09-18

CVE-2024-46742: In the Linux kernel, the following vulnerability has been resolved: smb/server: fix potential null-ptr-deref of lease_ctx_info in smb2_open() null-ptr-deref…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.24%
14.8th percentile
In the Linux kernel, the following vulnerability has been resolved: smb/server: fix potential null-ptr-deref of lease_ctx_info in smb2_open() null-ptr-deref will occur when (req_op_level == SMB2_OPLOCK_LEVEL_LEASE) and parse_lease_state() return NULL. Fix this by check if 'lease_ctx_info' is NULL. Additionally, remove the redundant parentheses in parse_durable_handle_context().

Affected

20 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.135-1 (bookworm)linux 6.1.135-1 (bookworm)
debianlinux-6.1< linux 6.1.135-1 (bookworm)linux 6.1.135-1 (bookworm)
linuxlinux
linuxlinux>= 0626e6641f6b467447c81dd7678a69c66f7746cf < 878f32878351104448b86ef5b85d1f8ed6f599fb878f32878351104448b86ef5b85d1f8ed6f599fb
linuxlinux>= 0626e6641f6b467447c81dd7678a69c66f7746cf < ec28c35029b7930f31117f9284874b63bea4f31bec28c35029b7930f31117f9284874b63bea4f31b
linuxlinux>= 0626e6641f6b467447c81dd7678a69c66f7746cf < 07f384c5be1f8633b13f0a22616e227570450bc607f384c5be1f8633b13f0a22616e227570450bc6
linuxlinux>= 0626e6641f6b467447c81dd7678a69c66f7746cf < 3b692794b81f2ecad69a4adbba687f3836824ada3b692794b81f2ecad69a4adbba687f3836824ada
linuxlinux>= 0626e6641f6b467447c81dd7678a69c66f7746cf < 4e8771a3666c8f216eefd6bd2fd50121c6c437db4e8771a3666c8f216eefd6bd2fd50121c6c437db
linuxlinux_kernel< 6.6.516.6.51
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.135-16.1.135-1
linuxlinux_kernel>= 0 < 6.10.11-16.10.11-1
linuxlinux_kernel>= 0 < 6.10.11-16.10.11-1
linuxlinux_kernel>= 0 < 5.15.0-144.1575.15.0-144.157
linuxlinux_kernel>= 6.7 < 6.10.106.10.10
msrcazl3_kernel_6.6.47.1-1_on_azure_linux_3.0
msrcazl3_kernel_6.6.51.1-5_on_azure_linux_3.0
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64
msrccbl2_kernel_5.15.180.1-1_on_cbl_mariner_2.0

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.