Back to search
CVE-2024-50086
Published: Oct 29, 2024
Modified: May 11, 2026
PUBLISHED
Description
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix user-after-free from session log off There is racy issue between smb2 session log off and smb2 session setup. It will cause user-after-free from session log off. This add session_lock when setting SMB2_SESSION_EXPIRED and referece count to session struct not to free session while it is being used.
| Vendor | Product | Versions |
|---|---|---|
Linux | Linux | affected 0626e6641f6b467447c81dd7678a69c66f7746cf - < 0f62358ce85b2d4c949ef1b648be01b29cec667aaffected 0626e6641f6b467447c81dd7678a69c66f7746cf - < a9839c37fd813b432988f58a9d9dd59253d3eb2caffected 0626e6641f6b467447c81dd7678a69c66f7746cf - < 5511999e9615e4318e9142d23b29bd1597befc08affected 0626e6641f6b467447c81dd7678a69c66f7746cf - < ee371898b53a9b9b51c02d22a8c31bfb86d45f0daffected 0626e6641f6b467447c81dd7678a69c66f7746cf - < 7aa8804c0b67b3cb263a472d17f2cb50d7f1a930 |
Linux | Linux | affected 5.15unaffected 0 - < 5.15unaffected 5.15.171 - <= 5.15.*unaffected 6.1.114 - <= 6.1.*unaffected 6.6.58 - <= 6.6.*+2 more versions |
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now