CVE-2024-50283

Source
https://cve.org/CVERecord?id=CVE-2024-50283
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-50283.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-50283
Downstream
Related
Published
2024-11-19T01:30:25.968Z
Modified
2026-05-28T03:53:40.926644350Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
ksmbd: fix slab-use-after-free in smb3_preauth_hash_rsp
Details

In the Linux kernel, the following vulnerability has been resolved:

ksmbd: fix slab-use-after-free in smb3preauthhash_rsp

ksmbdusersessionput should be called under smb3preauthhashrsp(). It will avoid freeing session before calling smb3preauthhash_rsp().

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/50xxx/CVE-2024-50283.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
0626e6641f6b467447c81dd7678a69c66f7746cf
Fixed
cb645064e0811053c94e86677f2e58ed29359d62
Fixed
f7557bbca40d4ca8bb1c6c940ac6c95078bd0827
Fixed
c6cdc08c25a868a08068dfc319fa9fce982b8e7f
Fixed
1b6ad475d4ed577d34e0157eb507be00c588bf5c
Fixed
b8fc56fbca7482c1e5c0e3351c6ae78982e25ada

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-50283.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.15.0
Fixed
5.15.174
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.117
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.61
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.11.8

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-50283.json"