PT-2024-6855 · Microsoft+3 · Windows Server 2022+3

Paulo Alcantara

+1

·

Published

2024-09-03

·

Updated

2026-02-21

·

CVE-2024-46796

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.6.52
Description The vulnerability is related to a use-after-free issue in the smb2 set path size() function. When smb2 compound op() is called with a valid @cfile and returns -EINVAL, the reference to @cfile is dropped, but the function may retry the operation without calling cifs get writable path() first. This can lead to a slab-use-after-free error, as seen in the KASAN splat when running fstests generic/013 against Windows Server 2022.
Recommendations To resolve the issue, update the Linux kernel to version 6.6.52 or later. As a temporary workaround, consider disabling the smb2 set path size() function until a patch is available. However, this may have unintended consequences and should be carefully evaluated before implementation.
Note: The provided information does not specify the exact vulnerable versions, but it mentions that the issue is fixed in Linux kernel version 6.6.52. Therefore, it is assumed that versions prior to 6.6.52 are vulnerable.

Exploit

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
ALT-PU-2024-12968
ALT-PU-2024-13260
BDU:2024-08076
CVE-2024-46796
MGASA-2024-0316
MGASA-2024-0318
OESA-2024-2219
OPENSUSE-SU-2025_1177-1
OPENSUSE-SU-2025_1178-1
OPENSUSE-SU-2025_1180-1
SUSE-SU-2025:01919-1
SUSE-SU-2025:1177-1
SUSE-SU-2025:1178-1
SUSE-SU-2025:1180-1
SUSE-SU-2025:20190-1
SUSE-SU-2025:20192-1
SUSE-SU-2025:20260-1
SUSE-SU-2025:20270-1
SUSE-SU-2025_1177-1
SUSE-SU-2025_1178-1
SUSE-SU-2025_1180-1

Affected Products

Alt Linux
Red Os
Suse
Windows Server 2022