cbcvebase.
CVE-2024-56627
published 2024-12-27

CVE-2024-56627: In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix Out-of-Bounds Read in ksmbd_vfs_stream_read An offset from client could be a…

PriorityP430high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.28%
20.0th percentile
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix Out-of-Bounds Read in ksmbd_vfs_stream_read An offset from client could be a negative value, It could lead to an out-of-bounds read from the stream_buf. Note that this issue is coming when setting 'vfs objects = streams_xattr parameter' in ksmbd.conf.

Affected

20 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.123-1 (bookworm)linux 6.1.123-1 (bookworm)
debianlinux-6.1< linux 6.1.123-1 (bookworm)linux 6.1.123-1 (bookworm)
linuxlinux
linuxlinux>= 0626e6641f6b467447c81dd7678a69c66f7746cf < 6bd1bf0e8c42f10a9a9679a4c103a9032d30594d6bd1bf0e8c42f10a9a9679a4c103a9032d30594d
linuxlinux>= 0626e6641f6b467447c81dd7678a69c66f7746cf < de4d790dcf53be41736239d7ee63849a16ff5d10de4d790dcf53be41736239d7ee63849a16ff5d10
linuxlinux>= 0626e6641f6b467447c81dd7678a69c66f7746cf < 27de4295522e9a33e4a3fc72f7b8193df9eebe4127de4295522e9a33e4a3fc72f7b8193df9eebe41
linuxlinux>= 0626e6641f6b467447c81dd7678a69c66f7746cf < 81eed631935f2c52cdaf6691c6d48e0b06e8ad7381eed631935f2c52cdaf6691c6d48e0b06e8ad73
linuxlinux>= 0626e6641f6b467447c81dd7678a69c66f7746cf < fc342cf86e2dc4d2edb0fc2ff5e28b6c7845adb9fc342cf86e2dc4d2edb0fc2ff5e28b6c7845adb9
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.123-16.1.123-1
linuxlinux_kernel>= 0 < 6.12.5-16.12.5-1
linuxlinux_kernel>= 0 < 6.12.5-16.12.5-1
linuxlinux_kernel>= 0 < 5.15.0-135.1465.15.0-135.146
linuxlinux_kernel>= 0 < 6.8.0-58.606.8.0-58.60
linuxlinux_kernel>= 5.15 < 5.15.1765.15.176
linuxlinux_kernel>= 5.16 < 6.1.1206.1.120
linuxlinux_kernel>= 6.2 < 6.6.666.6.66
linuxlinux_kernel>= 6.7 < 6.12.56.12.5
msrcazl3_kernel_6.6.64.2-9_on_azure_linux_3.0
msrccbl2_kernel_5.15.173.1-2_on_cbl_mariner_2.0

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.1HIGH
vendor_msrc7.1HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.