Tracker / CVE-2024-50286
CVE-2024-50286
Critical 9.8
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix slab-use-after-free in ksmbd_smb2_session_create There is a race condition between ksmbd_smb2_session_create and ksmbd_expire_session. This patch add missing sessions_table_lock while adding/deleting session from global session table.
Affected products and versions
| linux | linux_kernel |
|---|---|
| linux | linux_kernel · … → 6.1.117 |
| linux | linux_kernel · 6.2 → 6.6.61 |
| linux | linux_kernel · 6.7 → 6.11.8 |
Analysis
This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.