PT-2024-8306 · Linux+4 · Linux Kernel+4

Published

2024-04-19

·

Updated

2024-11-07

·

CVE-2024-26936

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to errors in reading beyond the allocated buffer memory in the smb2 allocate rsp buf() function of the ksmbd component. This can lead to a denial of service. The response buffer should be allocated before validating the request, but fields in the payload and smb2 header are used before this allocation, potentially causing out-of-bounds access. A patch adds simple buffer size validation to avoid this issue.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Out of bounds Read

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-09859
CVE-2024-26936
DSA-5680-1
MGASA-2024-0263
MGASA-2024-0266
OESA-2024-1737
OESA-2024-1738
USN-6893-1
USN-6893-2
USN-6893-3
USN-6918-1
USN-6950-1
USN-6950-2
USN-6950-3
USN-6950-4
USN-6956-1
USN-6957-1
USN-7019-1

Affected Products

Astra Linux
Linuxmint
Linux Kernel
Red Os
Ubuntu