Lucene search

K
ubuntucveUbuntu.comUB:CVE-2024-35869
HistoryMay 19, 2024 - 12:00 a.m.

CVE-2024-35869

2024-05-1900:00:00
ubuntu.com
ubuntu.com
6
linux kernel
smb client
vulnerability
cve-2024-35869
use-after-free
refcounted children
parent session
dfs mount

CVSS3

8.4

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

6.8

Confidence

High

EPSS

0

Percentile

15.5%

In the Linux kernel, the following vulnerability has been resolved: smb:
client: guarantee refcounted children from parent session Avoid potential
use-after-free bugs when walking DFS referrals, mounting and performing DFS
failover by ensuring that all children from parent @tcon->ses are also
refcounted. They’re all needed across the entire DFS mount. Get rid of
@tcon->dfs_ses_list while we’re at it, too.

CVSS3

8.4

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

6.8

Confidence

High

EPSS

0

Percentile

15.5%