CVE-2024-26594

HIGH

Linux Kernel < 5.15.149 Out-of-bounds Read in ksmbd Session Setup

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate mech token in session setup If client send invalid mech token in session setup request, ksmbd validate and make the error if it is invalid.

Scores

CVSS v3 7.1
EPSS 0.7839
EPSS Percentile 99.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-125
Status published
Products (17)
linux/Kernel 5.15.0 - 5.15.149linux
linux/Kernel 5.16.0 - 6.1.75linux
linux/Kernel 6.2.0 - 6.6.14linux
linux/Kernel 6.7.0 - 6.7.2linux
Linux/Linux < 5.15
Linux/Linux 0626e6641f6b467447c81dd7678a69c66f7746cf - 5e6dfec95833edc54c48605a98365a7325e5541e
Linux/Linux 0626e6641f6b467447c81dd7678a69c66f7746cf - 6eb8015492bcc84e40646390e50a862b2c0529c9
Linux/Linux 0626e6641f6b467447c81dd7678a69c66f7746cf - 92e470163d96df8db6c4fa0f484e4a229edb903d
Linux/Linux 0626e6641f6b467447c81dd7678a69c66f7746cf - a2b21ef1ea4cf632d19b3a7cc4d4245b8e63202a
Linux/Linux 0626e6641f6b467447c81dd7678a69c66f7746cf - dd1de9268745f0eac83a430db7afc32cbd62e84b
... and 7 more
Published Feb 23, 2024
Tracked Since Feb 18, 2026