cbcvebase.
CVE-2024-53179
published 2024-12-27

CVE-2024-53179: In the Linux kernel, the following vulnerability has been resolved: smb: client: fix use-after-free of signing key Customers have reported use-after-free in…

PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.25%
16.7th percentile
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix use-after-free of signing key Customers have reported use-after-free in @ses->auth_key.response with SMB2.1 + sign mounts which occurs due to following race: task A task B cifs_mount() dfs_mount_share() get_session() cifs_mount_get_session() cifs_send_recv() cifs_get_smb_ses() compound_send_recv() cifs_setup_session() smb2_setup_request() kfree_sensitive() smb2_calc_signature() crypto_shash_setkey() *UAF* Fix this by ensuring that we have a valid @ses->auth_key.response by checking whether @ses->ses_status is SES_GOOD or SES_EXITING with @ses->ses_lock held. After commit 24a9799aa8ef ("smb: client: fix UAF in smb2_reconnect_server()"), we made sure to call ->logoff() only when @ses was known to be good (e.g. valid ->auth_key.response), so it's safe to access signing key when @ses->ses_status == SES_EXITING.

Affected

13 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.12.3-1 (forky)linux 6.12.3-1 (forky)
linuxlinux
linuxlinux>= 32811d242ff6f28da2ab18c90a15e32fd958e774 < 39619c65ab4bbb3e78c818f537687653e112764d39619c65ab4bbb3e78c818f537687653e112764d
linuxlinux>= 32811d242ff6f28da2ab18c90a15e32fd958e774 < 0e2b654a3848bf9da3b0d54c1ccf3f1b8c6355910e2b654a3848bf9da3b0d54c1ccf3f1b8c635591
linuxlinux>= 32811d242ff6f28da2ab18c90a15e32fd958e774 < 343d7fe6df9e247671440a932b6a73af4fa86d95343d7fe6df9e247671440a932b6a73af4fa86d95
linuxlinux_kernel< 6.6.706.6.70
linuxlinux_kernel>= 0 < 6.12.3-16.12.3-1
linuxlinux_kernel>= 0 < 6.12.3-16.12.3-1
linuxlinux_kernel>= 0 < 6.8.0-60.636.8.0-60.63
linuxlinux_kernel>= 6.7 < 6.12.26.12.2
msrcazl3_kernel_6.6.64.2-9_on_azure_linux_3.0
msrcazl3_kernel_6.6.76.1-1_on_azure_linux_3.0
msrccbl2_kernel_5.15.182.1-1_on_cbl_mariner_2.0

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.