CVE-2024-26980

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix slab-out-of-bounds in smb2_allocate_rsp_buf If ->ProtocolId is SMB2_TRANSFORM_PROTO_NUM, smb2 request size validation could be skipped. if request size is smaller than sizeof(struct smb2_query_info_req), slab-out-of-bounds read can happen in smb2_allocate_rsp_buf(). This patch allocate response buffer after decrypting transform request. smb3_decrypt_req() will validate transform request size and avoid slab-out-of-bound in smb2_allocate_rsp_buf().
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.9:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.9:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.9:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.9:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.9:rc5:*:*:*:*:*:*

History

08 Apr 2025, 18:45

Type Values Removed Values Added
CWE CWE-125
First Time Linux linux Kernel
Linux
CPE cpe:2.3:o:linux:linux_kernel:6.9:rc5:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.9:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.9:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.9:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.9:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
References () https://git.kernel.org/stable/c/0977f89722eceba165700ea384f075143f012085 - () https://git.kernel.org/stable/c/0977f89722eceba165700ea384f075143f012085 - Patch
References () https://git.kernel.org/stable/c/3160d9734453a40db248487f8204830879c207f1 - () https://git.kernel.org/stable/c/3160d9734453a40db248487f8204830879c207f1 - Patch
References () https://git.kernel.org/stable/c/b80ba648714e6d790d69610cf14656be222d0248 - () https://git.kernel.org/stable/c/b80ba648714e6d790d69610cf14656be222d0248 - Patch
References () https://git.kernel.org/stable/c/c119f4ede3fa90a9463f50831761c28f989bfb20 - () https://git.kernel.org/stable/c/c119f4ede3fa90a9463f50831761c28f989bfb20 - Patch
References () https://git.kernel.org/stable/c/da21401372607c49972ea87a6edaafb36a17c325 - () https://git.kernel.org/stable/c/da21401372607c49972ea87a6edaafb36a17c325 - Patch

Information

Published : 2024-05-01 06:15

Updated : 2025-04-08 18:45


NVD link : CVE-2024-26980

Mitre link : CVE-2024-26980

CVE.ORG link : CVE-2024-26980


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-125

Out-of-bounds Read