Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential UAF in cifs_stats_proc_show() Skip sessions that are being teared down (status == SES_EXITING) to avoid UAF.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian | Debian Linux | 11.0 |
| Linux | Linux Kernel | >= 4.20, < 5.10.237 |
Related Weaknesses (CWE)
References
- https://git.kernel.org/stable/c/0865ffefea197b437ba78b5dd8d8e256253efd65Patch
- https://git.kernel.org/stable/c/16b7d785775eb03929766819415055e367398f49Patch
- https://git.kernel.org/stable/c/1e12f0d5c66f07c934041621351973a116fa13c7Patch
- https://git.kernel.org/stable/c/838ec01ea8d3deb5d123e8ed9022e8162dc3f503Patch
- https://git.kernel.org/stable/c/bb6570085826291dc392005f9fec16ea5da3c8adPatch
- https://git.kernel.org/stable/c/c3cf8b74c57924c0985e49a1fdf02d3395111f39Patch
- http://www.openwall.com/lists/oss-security/2024/05/29/2Mailing List
- http://www.openwall.com/lists/oss-security/2024/05/30/1Mailing List
- http://www.openwall.com/lists/oss-security/2024/05/30/2Mailing List
- https://git.kernel.org/stable/c/0865ffefea197b437ba78b5dd8d8e256253efd65Patch
- https://git.kernel.org/stable/c/16b7d785775eb03929766819415055e367398f49Patch
- https://git.kernel.org/stable/c/1e12f0d5c66f07c934041621351973a116fa13c7Patch
- https://git.kernel.org/stable/c/c3cf8b74c57924c0985e49a1fdf02d3395111f39Patch
- https://lists.debian.org/debian-lts-announce/2025/05/msg00030.htmlMailing ListThird Party Advisory
FAQ
What is CVE-2024-35867?
CVE-2024-35867 is a vulnerability with a CVSS score of 7.8 (HIGH). In the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential UAF in cifs_stats_proc_show() Skip sessions that are being teared down (status == SES_EXITING) to avoid...
How severe is CVE-2024-35867?
CVE-2024-35867 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-35867?
Check the references section above for vendor advisories and patch information. Affected products include: Debian Debian Linux, Linux Linux Kernel.