CVE-2024-44992

Severity CVSS v4.0:
Pending analysis
Type:
CWE-476 NULL Pointer Dereference
Publication date:
04/09/2024
Last modified:
06/09/2024

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> smb/client: avoid possible NULL dereference in cifs_free_subrequest()<br /> <br /> Clang static checker (scan-build) warning:<br /> cifsglob.h:line 890, column 3<br /> Access to field &amp;#39;ops&amp;#39; results in a dereference of a null pointer.<br /> <br /> Commit 519be989717c ("cifs: Add a tracepoint to track credits involved in<br /> R/W requests") adds a check for &amp;#39;rdata-&gt;server&amp;#39;, and let clang throw this<br /> warning about NULL dereference.<br /> <br /> When &amp;#39;rdata-&gt;credits.value != 0 &amp;&amp; rdata-&gt;server == NULL&amp;#39; happens,<br /> add_credits_and_wake_if() will call rdata-&gt;server-&gt;ops-&gt;add_credits().<br /> This will cause NULL dereference problem. Add a check for &amp;#39;rdata-&gt;server&amp;#39;<br /> to avoid NULL dereference.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.10 (including) 6.10.7 (excluding)
cpe:2.3:o:linux:linux_kernel:6.11:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.11:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.11:rc3:*:*:*:*:*:*