PT-2024-5399 · Linux+5 · Linux Kernel+5

Published

2024-03-16

·

Updated

2025-10-20

·

CVE-2024-26952

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to a potential out-of-bounds condition when the buffer offset fields of a few requests are invalid in the Linux kernel's ksmbd implementation. This could allow an attacker to impact the confidentiality, integrity, and availability of protected information. The vulnerability is associated with the smb2 get data area len() function in the fs/smb/server/smb2misc.c module.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Out of bounds Read

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
ALT-PU-2024-10855
AZL-42175
AZL-42207
BDU:2024-06043
BDU:2025-07830
CVE-2024-26952
DLA-4008-1
DSA-5818-1
OESA-2025-1093
OESA-2025-1095
OESA-2025-1096
OESA-2025-1097
USN-6816-1
USN-6817-1
USN-6817-2
USN-6817-3
USN-6878-1
USN-6923-1
USN-6923-2
USN-6927-1
USN-6956-1
USN-6957-1
USN-7019-1

Affected Products

Alt Linux
Astra Linux
Linuxmint
Linux Kernel
Red Os
Ubuntu