cbcvebase.
CVE-2024-50086
published 2024-10-29

CVE-2024-50086: In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix user-after-free from session log off There is racy issue between smb2 session…

PriorityP430high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
EPSS
0.21%
11.2th percentile
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix user-after-free from session log off There is racy issue between smb2 session log off and smb2 session setup. It will cause user-after-free from session log off. This add session_lock when setting SMB2_SESSION_EXPIRED and referece count to session struct not to free session while it is being used.

Affected

20 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.115-1 (bookworm)linux 6.1.115-1 (bookworm)
debianlinux-6.1< linux 6.1.115-1 (bookworm)linux 6.1.115-1 (bookworm)
linuxlinux
linuxlinux>= 0626e6641f6b467447c81dd7678a69c66f7746cf < 0f62358ce85b2d4c949ef1b648be01b29cec667a0f62358ce85b2d4c949ef1b648be01b29cec667a
linuxlinux>= 0626e6641f6b467447c81dd7678a69c66f7746cf < a9839c37fd813b432988f58a9d9dd59253d3eb2ca9839c37fd813b432988f58a9d9dd59253d3eb2c
linuxlinux>= 0626e6641f6b467447c81dd7678a69c66f7746cf < 5511999e9615e4318e9142d23b29bd1597befc085511999e9615e4318e9142d23b29bd1597befc08
linuxlinux>= 0626e6641f6b467447c81dd7678a69c66f7746cf < ee371898b53a9b9b51c02d22a8c31bfb86d45f0dee371898b53a9b9b51c02d22a8c31bfb86d45f0d
linuxlinux>= 0626e6641f6b467447c81dd7678a69c66f7746cf < 7aa8804c0b67b3cb263a472d17f2cb50d7f1a9307aa8804c0b67b3cb263a472d17f2cb50d7f1a930
linuxlinux_kernel< 6.1.1146.1.114
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.115-16.1.115-1
linuxlinux_kernel>= 0 < 6.11.5-16.11.5-1
linuxlinux_kernel>= 0 < 6.11.5-16.11.5-1
linuxlinux_kernel>= 0 < 5.15.0-133.1445.15.0-133.144
linuxlinux_kernel>= 0 < 6.8.0-56.586.8.0-56.58
linuxlinux_kernel>= 0 < 6.11.0-18.186.11.0-18.18
linuxlinux_kernel>= 6.2 < 6.6.586.6.58
linuxlinux_kernel>= 6.7 < 6.11.56.11.5

CVSS provenance

nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.0HIGH
vendor_redhat7.0HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.