cbcvebase.
CVE-2024-58087
published 2025-03-12

CVE-2024-58087: In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix racy issue from session lookup and expire Increment the session reference count…

PriorityP338high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
0.45%
36.8th percentile
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix racy issue from session lookup and expire Increment the session reference count within the lock for lookup to avoid racy issue with session expire.

Affected

18 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.123-1 (bookworm)linux 6.1.123-1 (bookworm)
linuxlinux
linuxlinux>= 0626e6641f6b467447c81dd7678a69c66f7746cf < 2107ab40629aeabbec369cf34b8cf0f288c3eb1b2107ab40629aeabbec369cf34b8cf0f288c3eb1b
linuxlinux>= 0626e6641f6b467447c81dd7678a69c66f7746cf < 37a0e2b362b3150317fb6e2139de67b1e29ae5ff37a0e2b362b3150317fb6e2139de67b1e29ae5ff
linuxlinux>= 0626e6641f6b467447c81dd7678a69c66f7746cf < 450a844c045ff0895d41b05a1cbe8febd1acfcfd450a844c045ff0895d41b05a1cbe8febd1acfcfd
linuxlinux>= 0626e6641f6b467447c81dd7678a69c66f7746cf < a39e31e22a535d47b14656a7d6a893c7f6cf758ca39e31e22a535d47b14656a7d6a893c7f6cf758c
linuxlinux>= 0626e6641f6b467447c81dd7678a69c66f7746cf < b95629435b84b9ecc0c765995204a4d8a913ed52b95629435b84b9ecc0c765995204a4d8a913ed52
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.123-16.1.123-1
linuxlinux_kernel>= 0 < 6.12.6-16.12.6-1
linuxlinux_kernel>= 0 < 6.12.6-16.12.6-1
linuxlinux_kernel>= 0 < 5.15.0-135.1465.15.0-135.146
linuxlinux_kernel>= 0 < 6.8.0-60.636.8.0-60.63
linuxlinux_kernel>= 5.15.145 < 5.15.1765.15.176
linuxlinux_kernel>= 6.1.29 < 6.1.1216.1.121
linuxlinux_kernel>= 6.2.16 < 6.36.3
linuxlinux_kernel>= 6.3.2 < 6.46.4
linuxlinux_kernel>= 6.7 < 6.12.66.12.6

CVSS provenance

nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
osv8.1HIGH
vendor_debian8.1HIGH
vendor_redhat8.1HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.