CVE-2024-50086

10/29/2024 1:15:00 AM
2 ماه قبل
یک ماه قبل
10
Reporter :cve@kernel.org
Modified :10/29/2024 1:15:00 AM
Problem Data :CWE-416

Description

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix user-after-free from session log off There is racy issue between smb2 session log off and smb2 session setup. It will cause user-after-free from session log off. This add session_lock when setting SMB2_SESSION_EXPIRED and referece count to session struct not to free session while it is being used.

Cvss Version 3.1

7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector Local
Attack Complexity High
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality Impact High
Integrity Impact High
Availability Impact High