CVE-2024-50286

Source
https://cve.org/CVERecord?id=CVE-2024-50286
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-50286.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-50286
Downstream
Related
Published
2024-11-19T01:30:29.948Z
Modified
2026-05-15T11:54:19.786171005Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
ksmbd: fix slab-use-after-free in ksmbd_smb2_session_create
Details

In the Linux kernel, the following vulnerability has been resolved:

ksmbd: fix slab-use-after-free in ksmbdsmb2session_create

There is a race condition between ksmbdsmb2sessioncreate and ksmbdexpiresession. This patch add missing sessionstable_lock while adding/deleting session from global session table.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/50xxx/CVE-2024-50286.json"
}
References

Affected packages

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.15.0
Fixed
6.1.117
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.61
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.11.8

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-50286.json"