CVE-2024-50283

HIGH

Linux Kernel < 6.1.117 - Use-After-Free in ksmbd_user_session_put

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix slab-use-after-free in smb3_preauth_hash_rsp ksmbd_user_session_put should be called under smb3_preauth_hash_rsp(). It will avoid freeing session before calling smb3_preauth_hash_rsp().

Scores

CVSS v3 7.8
EPSS 0.0024
EPSS Percentile 15.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-416
Status published
Products (18)
linux/Kernel 5.15.0 - 5.15.174linux
linux/Kernel 5.16.0 - 6.1.117linux
linux/Kernel 6.2.0 - 6.6.61linux
linux/Kernel 6.7.0 - 6.11.8linux
Linux/Linux < 5.15
Linux/Linux 0626e6641f6b467447c81dd7678a69c66f7746cf - 1b6ad475d4ed577d34e0157eb507be00c588bf5c
Linux/Linux 0626e6641f6b467447c81dd7678a69c66f7746cf - b8fc56fbca7482c1e5c0e3351c6ae78982e25ada
Linux/Linux 0626e6641f6b467447c81dd7678a69c66f7746cf - c6cdc08c25a868a08068dfc319fa9fce982b8e7f
Linux/Linux 0626e6641f6b467447c81dd7678a69c66f7746cf - cb645064e0811053c94e86677f2e58ed29359d62
Linux/Linux 0626e6641f6b467447c81dd7678a69c66f7746cf - f7557bbca40d4ca8bb1c6c940ac6c95078bd0827
... and 8 more
Published Nov 19, 2024
Tracked Since Feb 18, 2026