Out-of-Bounds Access Vulnerability in Linux Kernel ksmbd Affecting Various Distributions
CVE-2024-22705

7.8HIGH

Key Information:

Vendor
Linux
Vendor
CVE Published:
23 January 2024

Summary

A vulnerability in the ksmbd component of the Linux kernel, found in versions prior to 6.6.10, results in out-of-bounds access during the processing of SMB2 messages. Specifically, the handling of Name data and CreateContexts can lead to errors in memory allocation, potentially allowing malicious actors to exploit these weaknesses. The function smb2_get_data_area_len located in fs/smb/server/smb2misc.c is directly impacted, presenting risks to user data integrity and system stability. It is essential for system administrators and developers to be aware of this vulnerability and apply the necessary updates to safeguard against potential threats.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database
.