CVE-2024-26811

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
08/04/2024
Last modified:
04/11/2025

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> ksmbd: validate payload size in ipc response<br /> <br /> If installing malicious ksmbd-tools, ksmbd.mountd can return invalid ipc<br /> response to ksmbd kernel server. ksmbd should validate payload size of<br /> ipc response from ksmbd.mountd to avoid memory overrun or<br /> slab-out-of-bounds. This patch validate 3 ipc response that has payload.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.9 (excluding)
cpe:2.3:o:linux:linux_kernel:6.9:-:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.9:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.9:rc2:*:*:*:*:*:*