CVE-2024-50286

Source
https://cve.org/CVERecord?id=CVE-2024-50286
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-50286.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-50286
Downstream
Related
Published
2024-11-19T01:30:29.948Z
Modified
2026-05-28T03:52:56.691989602Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
ksmbd: fix slab-use-after-free in ksmbd_smb2_session_create
Details

In the Linux kernel, the following vulnerability has been resolved:

ksmbd: fix slab-use-after-free in ksmbdsmb2session_create

There is a race condition between ksmbdsmb2sessioncreate and ksmbdexpiresession. This patch add missing sessionstable_lock while adding/deleting session from global session table.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/50xxx/CVE-2024-50286.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
0626e6641f6b467447c81dd7678a69c66f7746cf
Fixed
f56446ba5378d19e31040b548a14ee9a8f1500ea
Fixed
e923503a56b3385b64ae492e3225e4623f560c5b
Fixed
e7a2ad2044377853cf8c59528dac808a08a99c72
Fixed
0a77715db22611df50b178374c51e2ba0d58866e

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-50286.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.15.0
Fixed
6.1.117
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.61
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.11.8

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-50286.json"