CVE-2024-58087

HIGH

Linux Kernel < 5.15.176 - Improper Locking

Title source: rule
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix racy issue from session lookup and expire Increment the session reference count within the lock for lookup to avoid racy issue with session expire.

Scores

CVSS v3 8.1
EPSS 0.0008
EPSS Percentile 23.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-667
Status published
Products (6)
linux/Kernel 5.15.0 - 5.15.176linux
linux/Kernel 5.16.0 - 6.1.121linux
linux/Kernel 6.2.0 - 6.6.67linux
linux/Kernel 6.7.0 - 6.12.6linux
linux/linux_kernel 6.13 rc1 (2 CPE variants)
linux/linux_kernel 5.15 - 5.15.176
Published Mar 12, 2025
Tracked Since Feb 18, 2026