Out-of-Bounds Access Vulnerability in Linux Kernel ksmbd Affecting Various Distributions
CVE-2024-22705
7.8HIGH
Summary
A vulnerability in the ksmbd component of the Linux kernel, found in versions prior to 6.6.10, results in out-of-bounds access during the processing of SMB2 messages. Specifically, the handling of Name data and CreateContexts can lead to errors in memory allocation, potentially allowing malicious actors to exploit these weaknesses. The function smb2_get_data_area_len located in fs/smb/server/smb2misc.c is directly impacted, presenting risks to user data integrity and system stability. It is essential for system administrators and developers to be aware of this vulnerability and apply the necessary updates to safeguard against potential threats.
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Collectors
NVD DatabaseMitre Database