PT-2024-34110 · Linux+5 · Linux Kernel+5
Norbert Szetei
·
Published
2024-11-04
·
Updated
2026-05-26
·
CVE-2024-50285
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
The Linux kernel's ksmbd component is affected by a memory exhaustion issue due to simultaneous SMB operations, which can consume excessive memory through the "ksmbd work cache", leading to an Out-of-Memory (OOM) issue.
The issue arises when a client sends multiple SMB operations to ksmbd, and the ksmbd credit mechanism is insufficient to handle this problem.
A patch has been added to check if the maximum credits are exceeded, preventing the issue by assuming one SMB request consumes at least one credit.
An exploit for this issue is available.
The affected software is the Linux kernel, specifically the ksmbd component.
#LinuxKernel #ksmbd #SMB #MemoryExhaustion #OOMIssue #LinuxSecurity
Exploit
Fix
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Debian
Linux Kernel
Linuxmint
Ubuntu