PT-2024-33827 · Linux+4 · Linux Kernel+4
Published
2024-09-03
·
Updated
2026-05-26
·
CVE-2024-49988
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
Linux kernel versions prior to 6.6.58
Description:
The issue is related to the ksmbd component in the Linux kernel. When sending an oplock break request,
opinfo->conn is used, but a freed ->conn can be used on multichannel, leading to potential issues. A patch has been added to include a reference count to the ksmbd conn struct, ensuring it can be freed when no longer used.Recommendations:
For versions prior to 6.6.58, update to version 6.6.58 or later to resolve the issue. As a temporary workaround, consider restricting the use of the
ksmbd component until a patch is available.Exploit
Fix
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Debian
Linuxmint
Linux Kernel
Ubuntu