PT-2024-37042 · Linux+7 · Linux Kernel+7
Published
2024-11-26
·
Updated
2026-03-13
·
CVE-2024-56729
CVSS v3.1
4.7
Medium
| Vector | AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
The issue relates to the SMB system in the Linux kernel. It involves the initialization of
cfid->tcon before performing network operations to avoid leaking a tcon reference when a lease break races with opening the cached directory. The processing of the leak break might take a reference to the tcon in cached dir lease break() and then fail to release the reference in cached dir offload close, since cfid->tcon is still NULL.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
DoS
Memory Leak
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Debian
Linuxmint
Linux Kernel
Red Hat
Suse
Ubuntu