PT-2024-34110 · Linux+5 · Linux Kernel+5

Norbert Szetei

·

Published

2024-11-04

·

Updated

2026-05-26

·

CVE-2024-50285

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The Linux kernel's ksmbd component is affected by a memory exhaustion issue due to simultaneous SMB operations, which can consume excessive memory through the "ksmbd work cache", leading to an Out-of-Memory (OOM) issue. The issue arises when a client sends multiple SMB operations to ksmbd, and the ksmbd credit mechanism is insufficient to handle this problem. A patch has been added to check if the maximum credits are exceeded, preventing the issue by assuming one SMB request consumes at least one credit. An exploit for this issue is available. The affected software is the Linux kernel, specifically the ksmbd component. #LinuxKernel #ksmbd #SMB #MemoryExhaustion #OOMIssue #LinuxSecurity

Exploit

Fix

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_12746
ALSA-2025_12752
ALSA-2025_12753
ALSA-2025_16880
ALT-PU-2024-17211
ALT-PU-2024-17891
ALT-PU-2025-12647
AZL-53570
AZL-53753
BDU:2025-12992
CVE-2024-50285
ECHO-743D-520B-0A7A
OESA-2024-2522
USN-7276-1
USN-7277-1
USN-7310-1
USN-7449-1
USN-7449-2
USN-7450-1
USN-7451-1
USN-7452-1
USN-7453-1
USN-7468-1
USN-7523-1
USN-7524-1
ZDI-24-1726

Affected Products

Alt Linux
Astra Linux
Debian
Linux Kernel
Linuxmint
Ubuntu