In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix potential UAF in cifsstatsproc_show()
Skip sessions that are being teared down (status == SES_EXITING) to avoid UAF.
{ "vanir_signatures": [ { "signature_type": "Line", "id": "CVE-2024-35867-049650d0", "deprecated": false, "digest": { "threshold": 0.9, "line_hashes": [ "296686110477930797183916307712206463050", "335167584156825741200961030146304821189", "328305038331829328601582189560743487139", "46988546275570998225455223121476693704" ] }, "target": { "file": "fs/smb/client/cifs_debug.c" }, "signature_version": "v1", "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@1e12f0d5c66f07c934041621351973a116fa13c7" }, { "signature_type": "Function", "id": "CVE-2024-35867-14287354", "deprecated": false, "digest": { "length": 2725.0, "function_hash": "170082997640740009324528470979843067070" }, "target": { "function": "cifs_stats_proc_show", "file": "fs/cifs/cifs_debug.c" }, "signature_version": "v1", "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@bb6570085826291dc392005f9fec16ea5da3c8ad" }, { "signature_type": "Function", "id": "CVE-2024-35867-143517e9", "deprecated": false, "digest": { "length": 2739.0, "function_hash": "314466147668895881555066163650735429886" }, "target": { "function": "cifs_stats_proc_show", "file": "fs/smb/client/cifs_debug.c" }, "signature_version": "v1", "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@16b7d785775eb03929766819415055e367398f49" }, { "signature_type": "Line", "id": "CVE-2024-35867-1b7b1fdd", "deprecated": false, "digest": { "threshold": 0.9, "line_hashes": [ "296686110477930797183916307712206463050", "335167584156825741200961030146304821189", "328305038331829328601582189560743487139", "46988546275570998225455223121476693704" ] }, "target": { "file": "fs/smb/client/cifs_debug.c" }, "signature_version": "v1", "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@16b7d785775eb03929766819415055e367398f49" }, { "signature_type": "Function", "id": "CVE-2024-35867-41c79461", "deprecated": false, "digest": { "length": 2739.0, "function_hash": "314466147668895881555066163650735429886" }, "target": { "function": "cifs_stats_proc_show", "file": "fs/smb/client/cifs_debug.c" }, "signature_version": "v1", "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@c3cf8b74c57924c0985e49a1fdf02d3395111f39" }, { "signature_type": "Line", "id": "CVE-2024-35867-6e1cf7f7", "deprecated": false, "digest": { "threshold": 0.9, "line_hashes": [ "296686110477930797183916307712206463050", "335167584156825741200961030146304821189", "328305038331829328601582189560743487139", "46988546275570998225455223121476693704" ] }, "target": { "file": "fs/smb/client/cifs_debug.c" }, "signature_version": "v1", "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@c3cf8b74c57924c0985e49a1fdf02d3395111f39" }, { "signature_type": "Line", "id": "CVE-2024-35867-6e6edb95", "deprecated": false, "digest": { "threshold": 0.9, "line_hashes": [ "296686110477930797183916307712206463050", "335167584156825741200961030146304821189", "328305038331829328601582189560743487139", "46988546275570998225455223121476693704" ] }, "target": { "file": "fs/smb/client/cifs_debug.c" }, "signature_version": "v1", "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@0865ffefea197b437ba78b5dd8d8e256253efd65" }, { "signature_type": "Function", "id": "CVE-2024-35867-aac6fd29", "deprecated": false, "digest": { "length": 2782.0, "function_hash": "217222041893040101175110543736947780949" }, "target": { "function": "cifs_stats_proc_show", "file": "fs/smb/client/cifs_debug.c" }, "signature_version": "v1", "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@0865ffefea197b437ba78b5dd8d8e256253efd65" }, { "signature_type": "Function", "id": "CVE-2024-35867-b394a4a4", "deprecated": false, "digest": { "length": 2762.0, "function_hash": "233122342266511527699760632150278175812" }, "target": { "function": "cifs_stats_proc_show", "file": "fs/cifs/cifs_debug.c" }, "signature_version": "v1", "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@838ec01ea8d3deb5d123e8ed9022e8162dc3f503" }, { "signature_type": "Function", "id": "CVE-2024-35867-dbc29635", "deprecated": false, "digest": { "length": 2782.0, "function_hash": "217222041893040101175110543736947780949" }, "target": { "function": "cifs_stats_proc_show", "file": "fs/smb/client/cifs_debug.c" }, "signature_version": "v1", "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@1e12f0d5c66f07c934041621351973a116fa13c7" } ] }