cbcvebase.
CVE-2024-57925
published 2025-01-19

CVE-2024-57925: In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix a missing return value check bug In the smb2_send_interim_resp(), if…

PriorityP429high7.1CVSS 3.1
AVLACLPRLUINSUCNIHAH
EPSS
0.21%
10.7th percentile
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix a missing return value check bug In the smb2_send_interim_resp(), if ksmbd_alloc_work_struct() fails to allocate a node, it returns a NULL pointer to the in_work pointer. This can lead to an illegal memory write of in_work->response_buf when allocate_interim_rsp_buf() attempts to perform a kzalloc() on it. To address this issue, incorporating a check for the return value of ksmbd_alloc_work_struct() ensures that the function returns immediately upon allocation failure, thereby preventing the aforementioned illegal memory access.

Affected

20 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.128-1 (bookworm)linux 6.1.128-1 (bookworm)
debianlinux-6.1< linux 6.1.128-1 (bookworm)linux 6.1.128-1 (bookworm)
linuxlinux
linuxlinux>= 041bba4414cda37d00063952c9bff9c3d5812a19 < 271ae0edbfc942795c162e6cf20d2bc02bd7fde4271ae0edbfc942795c162e6cf20d2bc02bd7fde4
linuxlinux>= 041bba4414cda37d00063952c9bff9c3d5812a19 < 2976e91a3e569cf2c92c9f71512c0ab1312fe9652976e91a3e569cf2c92c9f71512c0ab1312fe965
linuxlinux>= 041bba4414cda37d00063952c9bff9c3d5812a19 < 4c16e1cadcbcaf3c82d5fc310fbd34d0f5d0db7c4c16e1cadcbcaf3c82d5fc310fbd34d0f5d0db7c
linuxlinux>= 5.15.145 < 5.15.1775.15.177
linuxlinux>= 6.1.71 < 6.1.1256.1.125
linuxlinux>= 6f0207218c4c125f5bf32055ac4220b4ef3b7e67 < 781c743e18bfd9b7dc0383f036ae952bd1486f21781c743e18bfd9b7dc0383f036ae952bd1486f21
linuxlinux>= f8cf1ebb7de62c7d807707ce4abb69d483629263 < ee7e40f7fb17f08a8cbae50553e5c2e10ae32fceee7e40f7fb17f08a8cbae50553e5c2e10ae32fce
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.128-16.1.128-1
linuxlinux_kernel>= 0 < 6.12.10-16.12.10-1
linuxlinux_kernel>= 0 < 6.12.10-16.12.10-1
linuxlinux_kernel>= 0 < 5.15.0-135.1465.15.0-135.146
linuxlinux_kernel>= 0 < 6.8.0-60.636.8.0-60.63
linuxlinux_kernel>= 5.15.145 < 5.165.16
linuxlinux_kernel>= 6.1.71 < 6.1.1256.1.125
linuxlinux_kernel>= 6.6 < 6.6.726.6.72
linuxlinux_kernel>= 6.7 < 6.12.106.12.10

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.