cbcvebase.
CVE-2024-50151
published 2024-11-07

CVE-2024-50151: In the Linux kernel, the following vulnerability has been resolved: smb: client: fix OOBs when building SMB2_IOCTL request When using encryption, either…

PriorityP341high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.28%
20.1th percentile
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix OOBs when building SMB2_IOCTL request When using encryption, either enforced by the server or when using 'seal' mount option, the client will squash all compound request buffers down for encryption into a single iov in smb2_set_next_command(). SMB2_ioctl_init() allocates a small buffer (448 bytes) to hold the SMB2_IOCTL request in the first iov, and if the user passes an input buffer that is greater than 328 bytes, smb2_set_next_command() will end up writing off the end of @rqst->iov[0].iov_base as shown below: mount.cifs //srv/share /mnt -o ...,seal ln -s $(perl -e "print('a')for 1..1024") /mnt/link BUG: KASAN: slab-out-of-bounds in smb2_set_next_command.cold+0x1d6/0x24c [cifs] Write of size 4116 at addr ffff8881148fcab8 by task ln/859 CPU: 1 UID: 0 PID: 859 Comm: ln Not tainted 6.12.0-rc3 #1 Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-2.fc40 04/01/2014 Call Trace: dump_stack_lvl+0x5d/0x80 ? smb2_set_next_command.cold+0x1d6/0x24c [cifs] print_report+0x156/0x4d9 ? smb2_set_next_command.cold+0x1d6/0x24c [cifs] ? __virt_addr_valid+0x145/0x310 ? __phys_addr+0x46/0x90 ? smb2_set_next_command.cold+0x1d6/0x24c [cifs] kasan_report+0xda/0x110 ? smb2_set_next_command.cold+0x1d6/0x24c [cifs] kasan_check_range+0x10f/0x1f0 __asan_memcpy+0x3c/0x60 smb2_set_next_command.cold+0x1d6/0x24c [cifs] smb2_compound_op+0x238c/0x3840 [cifs] ? kasan_save_track+0x14/0x30 ? kasan_save_free_info+0x3b/0x70 ? vfs_symlink+0x1a1/0x2c0 ? do_symlinkat+0x108/0x1c0 ? __pfx_smb2_compound_op+0x10/0x10 [cifs] ? kmem_cache_free+0x118/0x3e0 ? cifs_get_writable_path+0xeb/0x1a0 [cifs] smb2_get_reparse_inode+0x423/0x540 [cifs] ? __pfx_smb2_get_reparse_inode+0x10/0x10 [cifs] ? rcu_is_watching+0x20/0x50 ? __kmalloc_noprof+0x37c/0x480 ? smb2_create_reparse_symlink+0x257/0x490 [cifs] ? smb2_create_reparse_symlink+0x38f/0x490 [cifs] smb2_create_reparse_symlink+0x38f/0x490 [cifs] ? __pfx_smb2_create_repar

Affected

31 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.115-1 (bookworm)linux 6.1.115-1 (bookworm)
debianlinux-6.1< linux 6.1.115-1 (bookworm)linux 6.1.115-1 (bookworm)
linuxlinux
linuxlinux>= e77fe73c7e38c36145825d84cfe385d400aba4fd < 6f0516ef1290da24b85461ed08a0938af7415e496f0516ef1290da24b85461ed08a0938af7415e49
linuxlinux>= e77fe73c7e38c36145825d84cfe385d400aba4fd < ed31aba8ce93472d9e16f5cff844ae7c94e9601ded31aba8ce93472d9e16f5cff844ae7c94e9601d
linuxlinux>= e77fe73c7e38c36145825d84cfe385d400aba4fd < e07d05b7f5ad9a503d9cab0afde2ab867bb65470e07d05b7f5ad9a503d9cab0afde2ab867bb65470
linuxlinux>= e77fe73c7e38c36145825d84cfe385d400aba4fd < 2ef632bfb888d1a14f81c1703817951e0bec55312ef632bfb888d1a14f81c1703817951e0bec5531
linuxlinux>= e77fe73c7e38c36145825d84cfe385d400aba4fd < b209c3a0bc3ac172265c7fa8309e5d00654f2510b209c3a0bc3ac172265c7fa8309e5d00654f2510
linuxlinux>= e77fe73c7e38c36145825d84cfe385d400aba4fd < fe92ddc1c32d4474e605e3a31a4afcd0e7d765ecfe92ddc1c32d4474e605e3a31a4afcd0e7d765ec
linuxlinux>= e77fe73c7e38c36145825d84cfe385d400aba4fd < 1ab60323c5201bef25f2a3dc0ccc404d9aca77f11ab60323c5201bef25f2a3dc0ccc404d9aca77f1
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.234-15.10.234-1
linuxlinux_kernel>= 0 < 6.1.115-16.1.115-1
linuxlinux_kernel>= 0 < 6.11.6-16.11.6-1
linuxlinux_kernel>= 0 < 6.11.6-16.11.6-1
linuxlinux_kernel>= 0 < 5.4.0-208.2285.4.0-208.228
linuxlinux_kernel>= 0 < 5.15.0-133.1445.15.0-133.144
linuxlinux_kernel>= 0 < 6.8.0-58.606.8.0-58.60
linuxlinux_kernel>= 0 < 6.11.0-18.186.11.0-18.18
linuxlinux_kernel>= 5.0 < 5.4.2855.4.285
linuxlinux_kernel>= 5.11 < 5.15.1705.15.170
linuxlinux_kernel>= 5.16 < 6.1.1156.1.115
linuxlinux_kernel>= 5.5 < 5.10.2295.10.229
linuxlinux_kernel>= 6.2 < 6.6.596.6.59
linuxlinux_kernel>= 6.7 < 6.11.66.11.6

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.