Review reviewHigh

CVE-2024-53186

Linux Linux, linux kernel

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in SMB request handling A race condition exists between SMB request handling in `ksmbd_conn_handler_loop()` and the freeing of `ksmbd_conn` in the workqueue handler `handle_ksmbd_work()`. This leads to a UAF. - KASAN: slab-use-after-free Read in handle_ksmbd_work - KASAN: slab-use-after-free in rtlock_slowlock_locked This race condition arises as follows: - `ksmbd_conn_handler_loop()` waits for `conn->r_count` to reach zero: `wait_event(conn->r_count_q, atomic_read(&conn->r_count) == 0);` - Meanwhi...

CVSS
7
EPSS
-
- percentile
CISA KEV
Not listed
Published
2024.12.27
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability-
Technical severityCVSS 7

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in SMB request handling A race condition exists between SMB request handling in `ksmbd_conn_handler_loop()` and the freeing of `ksmbd_conn` in the workqueue handler `handle_ksmbd_work()`. This leads to a UAF. - KASAN: slab-use-after-free Read in handle_ksmbd_work - KASAN: slab-use-after-free in rtlock_slowlock_locked This race condition arises as follows: - `ksmbd_conn_handler_loop()` waits for `conn->r_count` to reach zero: `wait_event(conn->r_count_q, atomic_read(&conn->r_count) == 0);` - Meanwhi...

Affected product and versions

Product
Linux Linux, linux kernel
Affected versions
>= 18f06bacc197d4ac9b518ad1c69999bc3d83e7aa < a96f9eb7add30ba0fafcfe7b7aca090978196800, >= e9dac92f4482a382e8c0fe1bc243da5fc3526b0c < f20b77f7897e6aab9ce5527e6016ad2be5d70a33, >= ee426bfb9d09b29987369b897fe9b6485ac2be27 < 96261adb998a3b513468b6ce17dbec76be5507d4, >= ee426bfb9d09b29987369b897fe9b6485ac2be27 < 9a8c5d89d327ff58e9b2517f8a6afb4181d32c6e, >= 9fd3cde4628bcd3549ab95061f2bab74d2ed4f3b, >= 6.6.55 < 6.6.64, >= 6.11.3 < 6.11.11, >= 6.10.14 < 6.11, >= 6.12, >= 6.12 < 6.12.2
Fixed versions
6.6.64, 6.11, 6.11.11, 6.12.2

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux Linux, linux kernel and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-362, CWE-416
CVE-2024-53186 — Linux Linux, linux kernel | SECUFOCUS NOW