cbcvebase.
CVE-2024-50047
published 2024-10-21

CVE-2024-50047: In the Linux kernel, the following vulnerability has been resolved: smb: client: fix UAF in async decryption Doing an async decryption (large read) crashes…

PriorityP340high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.23%
14.2th percentile
In the Linux kernel, the following vulnerability has been resolved:

smb: client: fix UAF in async decryption

Doing an async decryption (large read) crashes with a
slab-use-after-free way down in the crypto API.

Reproducer:
# mount.cifs -o ...,seal,esize=1 //srv/share /mnt
# dd if=/mnt/largefile of=/dev/null
...
[ 194.196391] ==================================================================
[ 194.196844] BUG: KASAN: slab-use-after-free in gf128mul_4k_lle+0xc1/0x110
[ 194.197269] Read of size 8 at addr ffff888112bd0448 by task kworker/u77:2/899
[ 194.197707]
[ 194.197818] CPU: 12 UID: 0 PID: 899 Comm: kworker/u77:2 Not tainted 6.11.0-lku-00028-gfca3ca14a17a-dirty #43
[ 194.198400] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.16.2-3-gd478f380-prebuilt.qemu.org 04/01/2014
[ 194.199046] Workqueue: smb3decryptd smb2_decrypt_offload [cifs]
[ 194.200032] Call Trace:
[ 194.200191]
[ 194.200327] dump_stack_lvl+0x4e/0x70
[ 194.200558] ? gf128mul_4k_lle+0xc1/0x110
[ 194.200809] print_report+0x174/0x505
[ 194.201040] ? __pfx__raw_spin_lock_irqsave+0x10/0x10
[ 194.201352] ? srso_return_thunk+0x5/0x5f
[ 194.201604] ? __virt_addr_valid+0xdf/0x1c0
[ 194.201868] ? gf128mul_4k_lle+0xc1/0x110
[ 194.202128] kasan_report+0xc8/0x150
[ 194.202361] ? gf128mul_4k_lle+0xc1/0x110
[ 194.202616] gf128mul_4k_lle+0xc1/0x110
[ 194.202863] ghash_update+0x184/0x210
[ 194.203103] shash_ahash_update+0x184/0x2a0
[ 194.203377] ? __pfx_shash_ahash_update+0x10/0x10
[ 194.203651] ? srso_return_thunk+0x5/0x5f
[ 194.203877] ? crypto_gcm_init_common+0x1ba/0x340
[ 194.204142] gcm_hash_assoc_remain_continue+0x10a/0x140
[ 194.204434] crypt_message+0xec1/0x10a0 [cifs]
[ 194.206489] ? __pfx_crypt_message+0x10/0x10 [cifs]
[ 194.208507] ? srso_return_thunk+0x5/0x5f
[ 194.209205] ? srso_return_thunk+0x5/0x5f
[ 194.209925] ? srso_return_thunk+0x5/0x5f
[ 194.210443] ? srso_return_thunk+0x5/0x5f
[ 194.211037] decrypt_raw_data+0x15f/0x250 [cifs]
[ 194.212906] ? __pfx_decrypt_raw_data+0x10/0x10 [cifs]

Affected

54 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.147-1 (bookworm)linux 6.1.147-1 (bookworm)
debianlinux< linux 6.1.128-1 (bookworm)linux 6.1.128-1 (bookworm)
debianlinux-6.1< linux 6.1.147-1 (bookworm)linux 6.1.147-1 (bookworm)
debianlinux-6.1< linux 6.1.128-1 (bookworm)linux 6.1.128-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux>= 0809fb86ad13b29e1d6d491364fc7ea4fb545995 < 15a0a5de49507062bc3be4014a403d8cea5533de15a0a5de49507062bc3be4014a403d8cea5533de
linuxlinux>= 5.10.237 < 5.10.2415.10.241
linuxlinux>= 5.15.181 < 5.15.1905.15.190
linuxlinux>= 6.1.128 < 6.1.1476.1.147
linuxlinux>= 6.11.4 < 6.126.12
linuxlinux>= 6.6.57 < 6.6.1006.6.100
linuxlinux>= 8f14a476abba13144df5434871a7225fd29af633 < 5d047b12f86cc3b9fde1171c02d9bccf4dba06325d047b12f86cc3b9fde1171c02d9bccf4dba0632
linuxlinux>= b0abcd65ec545701b8793e12bc27dc98042b151a < 2a76bc2b24ed889a689fb1c9015307bf16aafb5b2a76bc2b24ed889a689fb1c9015307bf16aafb5b
linuxlinux>= b0abcd65ec545701b8793e12bc27dc98042b151a < 8ac90f6824fc44d2e55a82503ddfc95defb19ae08ac90f6824fc44d2e55a82503ddfc95defb19ae0
linuxlinux>= b0abcd65ec545701b8793e12bc27dc98042b151a < b220bed63330c0e1733dc06ea8e75d5b9962b6b6b220bed63330c0e1733dc06ea8e75d5b9962b6b6
linuxlinux>= bce966530fd5542bbb422cb45ecb775f7a1a6bc3 < 9a1d3e8d40f151c2d5a5f40c410e6e433f62f4389a1d3e8d40f151c2d5a5f40c410e6e433f62f438
linuxlinux>= ef51c0d544b1518b35364480317ab6d3468f205d < 6550b2bef095d0dd2d2c8390d2ea4c38370288336550b2bef095d0dd2d2c8390d2ea4c3837028833
linuxlinux_kernel< 6.6.576.6.57
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.