Review reviewHigh

CVE-2024-35999

Linux Linux, linux kernel

In the Linux kernel, the following vulnerability has been resolved: smb3: missing lock when picking channel Coverity spotted a place where we should have been holding the channel lock when accessing the ses channel index. Addresses-Coverity: 1582039 ("Data race condition (MISSING_LOCK)")

CVSS
7.5
EPSS
0.38%
30.2% percentile
CISA KEV
Not listed
Published
2024.05.20
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.38%
Technical severityCVSS 7.5

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: smb3: missing lock when picking channel Coverity spotted a place where we should have been holding the channel lock when accessing the ses channel index. Addresses-Coverity: 1582039 ("Data race condition (MISSING_LOCK)")

Affected product and versions

Product
Linux Linux, linux kernel
Affected versions
>= 724244cdb3828522109c88e56a0242537aefabe9 < 98c7ed29cd754ae7475dc7cb3f33399fda902729, >= 724244cdb3828522109c88e56a0242537aefabe9 < 0fcf7e219448e937681216353c9a58abae6d3c2e, >= 724244cdb3828522109c88e56a0242537aefabe9 < 60ab245292280905603bc0d3654f4cf8fceccb00, >= 724244cdb3828522109c88e56a0242537aefabe9 < 8094a600245e9b28eb36a13036f202ad67c1f887, >= 3d74c2c917e4006a3bd660d2fc7829cb2ef64113, >= 5.15.27 < 5.16, >= 5.16, < 6.1.91, >= 6.2 < 6.6.30, >= 6.7 < 6.8.9, 6.9
Fixed versions
6.1.91, 6.6.30, 6.8.9

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux Linux, linux kernel and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE
CWE-667
CVE-2024-35999 — Linux Linux, linux kernel | SECUFOCUS NOW