CVE-2024-26828 (GCVE-0-2024-26828)
Vulnerability from cvelistv5
Published
2024-04-17 09:43
Modified
2026-08-05 11:27
Severity ?
Summary
In the Linux kernel, the following vulnerability has been resolved: cifs: fix underflow in parse_server_interfaces() In this loop, we step through the buffer and after each item we check if the size_left is greater than the minimum size we need. However, the problem is that "bytes_left" is type ssize_t while sizeof() is type size_t. That means that because of type promotion, the comparison is done as an unsigned and if we have negative bytes left the loop continues instead of ending.
Impacted products
Vendor Product Version
Linux Linux Version: fe856be475f7cf5ffcde57341d175ce9fd09434b
Version: fe856be475f7cf5ffcde57341d175ce9fd09434b
Version: fe856be475f7cf5ffcde57341d175ce9fd09434b
Version: fe856be475f7cf5ffcde57341d175ce9fd09434b
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "cvssV3_1": {
              "attackComplexity": "LOW",
              "attackVector": "ADJACENT_NETWORK",
              "availabilityImpact": "HIGH",
              "baseScore": 6.7,
              "baseSeverity": "MEDIUM",
              "confidentialityImpact": "NONE",
              "integrityImpact": "HIGH",
              "privilegesRequired": "LOW",
              "scope": "UNCHANGED",
              "userInteraction": "REQUIRED",
              "vectorString": "CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H",
              "version": "3.1"
            }
          },
          {
            "other": {
              "content": {
                "id": "CVE-2024-26828",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2024-06-12T17:36:16.490979Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "problemTypes": [
          {
            "descriptions": [
              {
                "description": "CWE-noinfo Not enough information",
                "lang": "en",
                "type": "CWE"
              }
            ]
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2024-11-04T18:28:47.130Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      },
      {
        "providerMetadata": {
          "dateUpdated": "2024-08-02T00:14:13.603Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/7190353835b4a219abb70f90b06cdcae97f11512"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/f7ff1c89fb6e9610d2b01c1821727729e6609308"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/df2af9fdbc4ddde18a3371c4ca1a86596e8be301"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/cffe487026be13eaf37ea28b783d9638ab147204"
          }
        ],
        "title": "CVE Program Container"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "fs/smb/client/smb2ops.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "7190353835b4a219abb70f90b06cdcae97f11512",
              "status": "affected",
              "version": "fe856be475f7cf5ffcde57341d175ce9fd09434b",
              "versionType": "git"
            },
            {
              "lessThan": "f7ff1c89fb6e9610d2b01c1821727729e6609308",
              "status": "affected",
              "version": "fe856be475f7cf5ffcde57341d175ce9fd09434b",
              "versionType": "git"
            },
            {
              "lessThan": "df2af9fdbc4ddde18a3371c4ca1a86596e8be301",
              "status": "affected",
              "version": "fe856be475f7cf5ffcde57341d175ce9fd09434b",
              "versionType": "git"
            },
            {
              "lessThan": "cffe487026be13eaf37ea28b783d9638ab147204",
              "status": "affected",
              "version": "fe856be475f7cf5ffcde57341d175ce9fd09434b",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "fs/smb/client/smb2ops.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4.18"
            },
            {
              "lessThan": "4.18",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.79",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.18",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.7.*",
              "status": "unaffected",
              "version": "6.7.6",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "6.8",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.79",
                  "versionStartIncluding": "4.18",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.18",
                  "versionStartIncluding": "4.18",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.7.6",
                  "versionStartIncluding": "4.18",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.8",
                  "versionStartIncluding": "4.18",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncifs: fix underflow in parse_server_interfaces()\n\nIn this loop, we step through the buffer and after each item we check\nif the size_left is greater than the minimum size we need.  However,\nthe problem is that \"bytes_left\" is type ssize_t while sizeof() is type\nsize_t.  That means that because of type promotion, the comparison is\ndone as an unsigned and if we have negative bytes left the loop\ncontinues instead of ending."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 9.4,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:N - The vulnerable parser consumes an SMB2 IOCTL response body received over TCP/445 from the remote SMB server, so a malicious or compromised server (or a MITM on an unsigned connection) triggers it purely with network data. No local access to the victim is required.\nAC:L - The server controls both the response length and every `Next` field, so making `bytes_left` underflow is a single deterministic value choice (e.g. buf_len=152, Next=160) with no race, timing, or memory-layout condition outside the attacker\u0027s control.\nPR:N - The attacker is the server side of the connection and needs no credentials or privileges on the victim host; it simply answers the client\u0027s own FSCTL_QUERY_NETWORK_INTERFACE_INFO request with a crafted reply.\nUI:N - Beyond the mount path, `smb2_query_server_interfaces()` re-issues the query from a self-re-arming cifsiod delayed work every 600 seconds, and `smb2_reconnect()` issues it on every tcon reconnect, so an already-mounted share is attacked with zero user action.\nS:U - The out-of-bounds read and the resulting crash are entirely within the kernel\u0027s own security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - The loop walks arbitrary kernel memory at an attacker-chosen stride and stores the OOB bytes as interface speeds and IPv4/IPv6 addresses in `ses-\u003eiface_list`, which is printed verbatim to world-readable `/proc/fs/cifs/DebugData` and used as multichannel connect targets \u2014 an unbounded, repeatable kernel heap disclosure primitive.\nI:L - There is no out-of-bounds write, but garbage harvested from unrelated kernel heap memory is installed as the session\u0027s authoritative interface list and drives which addresses the client opens additional SMB channels to, a limited unauthorized modification of client connection state.\nA:H - With `Next` up to 4 GiB the pointer walk dereferences unmapped memory and oopses the kernel, and the loop can only exit when an OOB `Next` is zero, additionally causing unbounded `iface_list`/`iface_count` growth from a workqueue context."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T11:27:41.706Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/7190353835b4a219abb70f90b06cdcae97f11512"
        },
        {
          "url": "https://git.kernel.org/stable/c/f7ff1c89fb6e9610d2b01c1821727729e6609308"
        },
        {
          "url": "https://git.kernel.org/stable/c/df2af9fdbc4ddde18a3371c4ca1a86596e8be301"
        },
        {
          "url": "https://git.kernel.org/stable/c/cffe487026be13eaf37ea28b783d9638ab147204"
        }
      ],
      "title": "cifs: fix underflow in parse_server_interfaces()",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2024-26828",
    "datePublished": "2024-04-17T09:43:52.995Z",
    "dateReserved": "2024-02-19T14:20:24.181Z",
    "dateUpdated": "2026-08-05T11:27:41.706Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "vulnrichment": {
      "containers": "{\"adp\": [{\"title\": \"CVE Program Container\", \"references\": [{\"url\": \"https://git.kernel.org/stable/c/7190353835b4a219abb70f90b06cdcae97f11512\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/f7ff1c89fb6e9610d2b01c1821727729e6609308\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/df2af9fdbc4ddde18a3371c4ca1a86596e8be301\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/cffe487026be13eaf37ea28b783d9638ab147204\", \"tags\": [\"x_transferred\"]}], \"providerMetadata\": {\"orgId\": \"af854a3a-2127-422b-91ae-364da2661108\", \"shortName\": \"CVE\", \"dateUpdated\": \"2024-08-02T00:14:13.603Z\"}}, {\"title\": \"CISA ADP Vulnrichment\", \"metrics\": [{\"cvssV3_1\": {\"scope\": \"UNCHANGED\", \"version\": \"3.1\", \"baseScore\": 6.7, \"attackVector\": \"ADJACENT_NETWORK\", \"baseSeverity\": \"MEDIUM\", \"vectorString\": \"CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H\", \"integrityImpact\": \"HIGH\", \"userInteraction\": \"REQUIRED\", \"attackComplexity\": \"LOW\", \"availabilityImpact\": \"HIGH\", \"privilegesRequired\": \"LOW\", \"confidentialityImpact\": \"NONE\"}}, {\"other\": {\"type\": \"ssvc\", \"content\": {\"id\": \"CVE-2024-26828\", \"role\": \"CISA Coordinator\", \"options\": [{\"Exploitation\": \"none\"}, {\"Automatable\": \"no\"}, {\"Technical Impact\": \"partial\"}], \"version\": \"2.0.3\", \"timestamp\": \"2024-06-12T17:36:16.490979Z\"}}}], \"problemTypes\": [{\"descriptions\": [{\"lang\": \"en\", \"type\": \"CWE\", \"description\": \"CWE-noinfo Not enough information\"}]}], \"providerMetadata\": {\"orgId\": \"134c704f-9b21-4f2e-91b3-4a467353bcc0\", \"shortName\": \"CISA-ADP\", \"dateUpdated\": \"2024-06-12T17:36:19.978Z\"}}], \"cna\": {\"title\": \"cifs: fix underflow in parse_server_interfaces()\", \"metrics\": [{\"cvssV3_1\": {\"version\": \"3.1\", \"baseScore\": 9.4, \"baseSeverity\": \"CRITICAL\", \"vectorString\": \"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H\"}, \"scenarios\": [{\"lang\": \"en\", \"value\": \"AV:N - The vulnerable parser consumes an SMB2 IOCTL response body received over TCP/445 from the remote SMB server, so a malicious or compromised server (or a MITM on an unsigned connection) triggers it purely with network data. No local access to the victim is required.\\nAC:L - The server controls both the response length and every `Next` field, so making `bytes_left` underflow is a single deterministic value choice (e.g. buf_len=152, Next=160) with no race, timing, or memory-layout condition outside the attacker\u0027s control.\\nPR:N - The attacker is the server side of the connection and needs no credentials or privileges on the victim host; it simply answers the client\u0027s own FSCTL_QUERY_NETWORK_INTERFACE_INFO request with a crafted reply.\\nUI:N - Beyond the mount path, `smb2_query_server_interfaces()` re-issues the query from a self-re-arming cifsiod delayed work every 600 seconds, and `smb2_reconnect()` issues it on every tcon reconnect, so an already-mounted share is attacked with zero user action.\\nS:U - The out-of-bounds read and the resulting crash are entirely within the kernel\u0027s own security authority; no VM, IOMMU, or sandbox boundary is crossed.\\nC:H - The loop walks arbitrary kernel memory at an attacker-chosen stride and stores the OOB bytes as interface speeds and IPv4/IPv6 addresses in `ses-\u003eiface_list`, which is printed verbatim to world-readable `/proc/fs/cifs/DebugData` and used as multichannel connect targets \\u2014 an unbounded, repeatable kernel heap disclosure primitive.\\nI:L - There is no out-of-bounds write, but garbage harvested from unrelated kernel heap memory is installed as the session\u0027s authoritative interface list and drives which addresses the client opens additional SMB channels to, a limited unauthorized modification of client connection state.\\nA:H - With `Next` up to 4 GiB the pointer walk dereferences unmapped memory and oopses the kernel, and the loop can only exit when an OOB `Next` is zero, additionally causing unbounded `iface_list`/`iface_count` growth from a workqueue context.\"}]}], \"affected\": [{\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"fe856be475f7cf5ffcde57341d175ce9fd09434b\", \"lessThan\": \"7190353835b4a219abb70f90b06cdcae97f11512\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"fe856be475f7cf5ffcde57341d175ce9fd09434b\", \"lessThan\": \"f7ff1c89fb6e9610d2b01c1821727729e6609308\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"fe856be475f7cf5ffcde57341d175ce9fd09434b\", \"lessThan\": \"df2af9fdbc4ddde18a3371c4ca1a86596e8be301\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"fe856be475f7cf5ffcde57341d175ce9fd09434b\", \"lessThan\": \"cffe487026be13eaf37ea28b783d9638ab147204\", \"versionType\": \"git\"}], \"programFiles\": [\"fs/smb/client/smb2ops.c\"], \"defaultStatus\": \"unaffected\"}, {\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"4.18\"}, {\"status\": \"unaffected\", \"version\": \"0\", \"lessThan\": \"4.18\", \"versionType\": \"semver\"}, {\"status\": \"unaffected\", \"version\": \"6.1.79\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.1.*\"}, {\"status\": \"unaffected\", \"version\": \"6.6.18\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.6.*\"}, {\"status\": \"unaffected\", \"version\": \"6.7.6\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.7.*\"}, {\"status\": \"unaffected\", \"version\": \"6.8\", \"versionType\": \"original_commit_for_fix\", \"lessThanOrEqual\": \"*\"}], \"programFiles\": [\"fs/smb/client/smb2ops.c\"], \"defaultStatus\": \"affected\"}], \"references\": [{\"url\": \"https://git.kernel.org/stable/c/7190353835b4a219abb70f90b06cdcae97f11512\"}, {\"url\": \"https://git.kernel.org/stable/c/f7ff1c89fb6e9610d2b01c1821727729e6609308\"}, {\"url\": \"https://git.kernel.org/stable/c/df2af9fdbc4ddde18a3371c4ca1a86596e8be301\"}, {\"url\": \"https://git.kernel.org/stable/c/cffe487026be13eaf37ea28b783d9638ab147204\"}], \"x_generator\": {\"engine\": \"bippy-1.2.0\"}, \"descriptions\": [{\"lang\": \"en\", \"value\": \"In the Linux kernel, the following vulnerability has been resolved:\\n\\ncifs: fix underflow in parse_server_interfaces()\\n\\nIn this loop, we step through the buffer and after each item we check\\nif the size_left is greater than the minimum size we need.  However,\\nthe problem is that \\\"bytes_left\\\" is type ssize_t while sizeof() is type\\nsize_t.  That means that because of type promotion, the comparison is\\ndone as an unsigned and if we have negative bytes left the loop\\ncontinues instead of ending.\"}], \"cpeApplicability\": [{\"nodes\": [{\"negate\": false, \"cpeMatch\": [{\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.1.79\", \"versionStartIncluding\": \"4.18\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.6.18\", \"versionStartIncluding\": \"4.18\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.7.6\", \"versionStartIncluding\": \"4.18\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.8\", \"versionStartIncluding\": \"4.18\"}], \"operator\": \"OR\"}]}], \"providerMetadata\": {\"orgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"shortName\": \"Linux\", \"dateUpdated\": \"2026-08-05T11:27:41.706Z\"}}}",
      "cveMetadata": "{\"cveId\": \"CVE-2024-26828\", \"state\": \"PUBLISHED\", \"dateUpdated\": \"2026-08-05T11:27:41.706Z\", \"dateReserved\": \"2024-02-19T14:20:24.181Z\", \"assignerOrgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"datePublished\": \"2024-04-17T09:43:52.995Z\", \"assignerShortName\": \"Linux\"}",
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }
  }
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…