cbcvebase.
CVE-2024-50284
published 2024-11-19

CVE-2024-50284: In the Linux kernel, the following vulnerability has been resolved: ksmbd: Fix the missing xa_store error check xa_store() can fail, it return xa_err(-EINVAL)…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.54%
42.3th percentile
In the Linux kernel, the following vulnerability has been resolved: ksmbd: Fix the missing xa_store error check xa_store() can fail, it return xa_err(-EINVAL) if the entry cannot be stored in an XArray, or xa_err(-ENOMEM) if memory allocation failed, so check error for xa_store() to fix it.

Affected

30 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.119-1 (bookworm)linux 6.1.119-1 (bookworm)
debianlinux-6.1< linux 6.1.119-1 (bookworm)linux 6.1.119-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux>= 052b41ef2abe274f068e892aee81406f11bd1f3a < d8664ce789bd46290c59a00da6897252f92c237dd8664ce789bd46290c59a00da6897252f92c237d
linuxlinux>= 5.15.145 < 5.165.16
linuxlinux>= 6.1.71 < 6.1.1176.1.117
linuxlinux>= b685757c7b08d5073046fb379be965fd6c06aafc < 726c1568b9145fa13ee248df184b186c382a7ff8726c1568b9145fa13ee248df184b186c382a7ff8
linuxlinux>= b685757c7b08d5073046fb379be965fd6c06aafc < c2a232c4f790f4bcd4d218904c56ac7a39a448f5c2a232c4f790f4bcd4d218904c56ac7a39a448f5
linuxlinux>= b685757c7b08d5073046fb379be965fd6c06aafc < 3abab905b14f4ba756d413f37f1fb02b708eee933abab905b14f4ba756d413f37f1fb02b708eee93
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.119-16.1.119-1
linuxlinux_kernel>= 0 < 6.11.9-16.11.9-1
linuxlinux_kernel>= 0 < 6.11.9-16.11.9-1
linuxlinux_kernel>= 0 < 6.8.0-58.606.8.0-58.60
linuxlinux_kernel>= 0 < 6.11.0-18.186.11.0-18.18
linuxlinux_kernel>= 5.15.145 < 5.165.16
linuxlinux_kernel>= 6.1.71 < 6.1.1176.1.117
linuxlinux_kernel>= 6.3 < 6.6.616.6.61
linuxlinux_kernel>= 6.7 < 6.11.86.11.8

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.