Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential UAF in smb2_is_valid_lease_break() Skip sessions that are being teared down (status == SES_EXITING) to avoid UAF.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | < 6.1.85 |
Related Weaknesses (CWE)
References
- https://git.kernel.org/stable/c/705c76fbf726c7a2f6ff9143d4013b18daaaebf1Patch
- https://git.kernel.org/stable/c/a8344e2b69bde63f713b0aa796d70dbeadffddfbPatch
- https://git.kernel.org/stable/c/c868cabdf6fdd61bea54532271f4708254e57fc5Patch
- https://git.kernel.org/stable/c/f92739fdd4522c4291277136399353d7c341fae4Patch
- https://git.kernel.org/stable/c/705c76fbf726c7a2f6ff9143d4013b18daaaebf1Patch
- https://git.kernel.org/stable/c/a8344e2b69bde63f713b0aa796d70dbeadffddfbPatch
- https://git.kernel.org/stable/c/c868cabdf6fdd61bea54532271f4708254e57fc5Patch
- https://git.kernel.org/stable/c/f92739fdd4522c4291277136399353d7c341fae4Patch
FAQ
What is CVE-2024-35864?
CVE-2024-35864 is a vulnerability with a CVSS score of 7.8 (HIGH). In the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential UAF in smb2_is_valid_lease_break() Skip sessions that are being teared down (status == SES_EXITING) to ...
How severe is CVE-2024-35864?
CVE-2024-35864 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-35864?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.