In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix potential UAF in cifsdebugfilesprocshow()
Skip sessions that are being teared down (status == SES_EXITING) to avoid UAF.
[
{
"id": "CVE-2024-26928-026fcbbd",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@ca545b7f0823f19db0f1148d59bc5e1a56634502",
"signature_type": "Line",
"target": {
"file": "fs/smb/client/cifs_debug.c"
},
"deprecated": false,
"digest": {
"line_hashes": [
"187113356252891967507170384921436064695",
"103790744240366129478044222835065088681",
"196529484071390281076842442486063457091",
"225487858487858105384164297348933114912"
],
"threshold": 0.9
},
"signature_version": "v1"
},
{
"id": "CVE-2024-26928-0b4ff058",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@229042314602db62559ecacba127067c22ee7b88",
"signature_type": "Function",
"target": {
"file": "fs/smb/client/cifs_debug.c",
"function": "cifs_debug_files_proc_show"
},
"deprecated": false,
"digest": {
"length": 1245.0,
"function_hash": "186313031616370171338402040519982004120"
},
"signature_version": "v1"
},
{
"id": "CVE-2024-26928-11cded3a",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@a140224bcf87eb98a87b67ff4c6826c57e47b704",
"signature_type": "Function",
"target": {
"file": "fs/cifs/cifs_debug.c",
"function": "cifs_debug_files_proc_show"
},
"deprecated": false,
"digest": {
"length": 1362.0,
"function_hash": "79508164223098453759603313656917439361"
},
"signature_version": "v1"
},
{
"id": "CVE-2024-26928-278b77c7",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@ca545b7f0823f19db0f1148d59bc5e1a56634502",
"signature_type": "Function",
"target": {
"file": "fs/smb/client/cifs_debug.c",
"function": "cifs_debug_files_proc_show"
},
"deprecated": false,
"digest": {
"length": 1245.0,
"function_hash": "186313031616370171338402040519982004120"
},
"signature_version": "v1"
},
{
"id": "CVE-2024-26928-3f1cf0cc",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@229042314602db62559ecacba127067c22ee7b88",
"signature_type": "Line",
"target": {
"file": "fs/smb/client/cifs_debug.c"
},
"deprecated": false,
"digest": {
"line_hashes": [
"187113356252891967507170384921436064695",
"103790744240366129478044222835065088681",
"196529484071390281076842442486063457091",
"225487858487858105384164297348933114912"
],
"threshold": 0.9
},
"signature_version": "v1"
},
{
"id": "CVE-2024-26928-4710cf3b",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@a140224bcf87eb98a87b67ff4c6826c57e47b704",
"signature_type": "Line",
"target": {
"file": "fs/cifs/cifsglob.h"
},
"deprecated": false,
"digest": {
"line_hashes": [
"277549994795975370365126985551670387564"
],
"threshold": 0.9
},
"signature_version": "v1"
},
{
"id": "CVE-2024-26928-645aaeda",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@8f8718afd446cd4ea3b62bacc3eec09f8aae85ee",
"signature_type": "Line",
"target": {
"file": "fs/cifs/cifs_debug.c"
},
"deprecated": false,
"digest": {
"line_hashes": [
"281018317304127459616205510469026607663",
"259584086166653404497628875646140959063",
"116872726873910548484820163612428908758",
"319116384796632832248787052402549326707"
],
"threshold": 0.9
},
"signature_version": "v1"
},
{
"id": "CVE-2024-26928-6db5d4f5",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@a65f2b56334ba4dc30bd5ee9ce5b2691b973344d",
"signature_type": "Line",
"target": {
"file": "fs/smb/client/cifsglob.h"
},
"deprecated": false,
"digest": {
"line_hashes": [
"66695350772810841447376401613169504227"
],
"threshold": 0.9
},
"signature_version": "v1"
},
{
"id": "CVE-2024-26928-906046d0",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@229042314602db62559ecacba127067c22ee7b88",
"signature_type": "Line",
"target": {
"file": "fs/smb/client/cifsglob.h"
},
"deprecated": false,
"digest": {
"line_hashes": [
"277549994795975370365126985551670387564"
],
"threshold": 0.9
},
"signature_version": "v1"
},
{
"id": "CVE-2024-26928-960bd77b",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@8f8718afd446cd4ea3b62bacc3eec09f8aae85ee",
"signature_type": "Function",
"target": {
"file": "fs/cifs/cifs_debug.c",
"function": "cifs_debug_files_proc_show"
},
"deprecated": false,
"digest": {
"length": 1387.0,
"function_hash": "339502132911282206780352526466322610780"
},
"signature_version": "v1"
},
{
"id": "CVE-2024-26928-a8490515",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@a140224bcf87eb98a87b67ff4c6826c57e47b704",
"signature_type": "Line",
"target": {
"file": "fs/cifs/cifs_debug.c"
},
"deprecated": false,
"digest": {
"line_hashes": [
"51298925709214196775702303649365724718",
"326052841960057420655396482761998851159",
"116872726873910548484820163612428908758",
"319116384796632832248787052402549326707"
],
"threshold": 0.9
},
"signature_version": "v1"
},
{
"id": "CVE-2024-26928-b0a0a3b7",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@ca545b7f0823f19db0f1148d59bc5e1a56634502",
"signature_type": "Line",
"target": {
"file": "fs/smb/client/cifsglob.h"
},
"deprecated": false,
"digest": {
"line_hashes": [
"205553661941318298473352406809394070579"
],
"threshold": 0.9
},
"signature_version": "v1"
},
{
"id": "CVE-2024-26928-d6a784fa",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@a65f2b56334ba4dc30bd5ee9ce5b2691b973344d",
"signature_type": "Line",
"target": {
"file": "fs/smb/client/cifs_debug.c"
},
"deprecated": false,
"digest": {
"line_hashes": [
"187113356252891967507170384921436064695",
"103790744240366129478044222835065088681",
"196529484071390281076842442486063457091",
"225487858487858105384164297348933114912"
],
"threshold": 0.9
},
"signature_version": "v1"
},
{
"id": "CVE-2024-26928-dd9c55bc",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@8f8718afd446cd4ea3b62bacc3eec09f8aae85ee",
"signature_type": "Line",
"target": {
"file": "fs/cifs/cifsglob.h"
},
"deprecated": false,
"digest": {
"line_hashes": [
"277549994795975370365126985551670387564"
],
"threshold": 0.9
},
"signature_version": "v1"
},
{
"id": "CVE-2024-26928-e6c42dc0",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@a65f2b56334ba4dc30bd5ee9ce5b2691b973344d",
"signature_type": "Function",
"target": {
"file": "fs/smb/client/cifs_debug.c",
"function": "cifs_debug_files_proc_show"
},
"deprecated": false,
"digest": {
"length": 1245.0,
"function_hash": "186313031616370171338402040519982004120"
},
"signature_version": "v1"
}
]