CVE-2024-35863 (GCVE-0-2024-35863)
Vulnerability from cvelistv5
Published
2024-05-19 08:34
Modified
2026-08-05 11:30
Severity ?
Summary
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential UAF in is_valid_oplock_break() Skip sessions that are being teared down (status == SES_EXITING) to avoid UAF.
Impacted products
Vendor Product Version
Linux Linux Version: 7f48558e6489d032b1584b0cc9ac4bb11072c034
Version: 7f48558e6489d032b1584b0cc9ac4bb11072c034
Version: 7f48558e6489d032b1584b0cc9ac4bb11072c034
Version: 7f48558e6489d032b1584b0cc9ac4bb11072c034
Version: a67172a013953664b1dad03c648200c70b90506c
Version: 3.12.48   
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "providerMetadata": {
          "dateUpdated": "2024-08-02T03:21:48.533Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/494c91e1e9413b407d12166a61b84200d4d54fac"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/0a15ba88a32fa7a516aff7ffd27befed5334dff2"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/16d58c6a7db5050b9638669084b63fc05f951825"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/69ccf040acddf33a3a85ec0f6b45ef84b0f7ec29"
          }
        ],
        "title": "CVE Program Container"
      },
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2024-35863",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2024-09-10T15:41:24.364295Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2024-09-11T17:33:16.978Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "fs/smb/client/misc.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "494c91e1e9413b407d12166a61b84200d4d54fac",
              "status": "affected",
              "version": "7f48558e6489d032b1584b0cc9ac4bb11072c034",
              "versionType": "git"
            },
            {
              "lessThan": "0a15ba88a32fa7a516aff7ffd27befed5334dff2",
              "status": "affected",
              "version": "7f48558e6489d032b1584b0cc9ac4bb11072c034",
              "versionType": "git"
            },
            {
              "lessThan": "16d58c6a7db5050b9638669084b63fc05f951825",
              "status": "affected",
              "version": "7f48558e6489d032b1584b0cc9ac4bb11072c034",
              "versionType": "git"
            },
            {
              "lessThan": "69ccf040acddf33a3a85ec0f6b45ef84b0f7ec29",
              "status": "affected",
              "version": "7f48558e6489d032b1584b0cc9ac4bb11072c034",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "a67172a013953664b1dad03c648200c70b90506c",
              "versionType": "git"
            },
            {
              "lessThan": "3.13",
              "status": "affected",
              "version": "3.12.48",
              "versionType": "semver"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "fs/smb/client/misc.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "3.13"
            },
            {
              "lessThan": "3.13",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.85",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.26",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.8.*",
              "status": "unaffected",
              "version": "6.8.5",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "6.9",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.85",
                  "versionStartIncluding": "3.13",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.26",
                  "versionStartIncluding": "3.13",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.8.5",
                  "versionStartIncluding": "3.13",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.9",
                  "versionStartIncluding": "3.13",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionStartIncluding": "3.12.48",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix potential UAF in is_valid_oplock_break()\n\nSkip sessions that are being teared down (status == SES_EXITING) to\navoid UAF."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:N - The vulnerable walk is executed by the cifs demultiplex kernel thread directly on an unsolicited SMB1 LOCKING_ANDX frame read off the TCP/445 socket, so it is driven entirely by data from a remote SMB peer. A malicious/compromised file server, or an off-path/MITM injector on the unsigned SMB1 stream, reaches it over the network.\nAC:L - The attacker controls both sides of the race: it can force repeated session teardowns (DFS referrals/failover, forced reconnects, multiuser tlink expiry) and can hold the SES_EXITING window open arbitrarily long by stalling the blocking SMB LOGOFF reply that `__cifs_put_smb_ses()` waits on before unlinking and freeing the session, while flooding oplock-break frames. Attempts are unlimited and require no condition outside the attacker\u0027s influence.\nPR:N - No credentials or privileges on the victim client are needed \u2014 the oplock-break frame is dispatched with no UID/session lookup and no signature validation, so any peer able to put bytes on the client\u0027s SMB connection triggers the walk. The attacking entity is the server side of an existing mount, which holds no privilege on the vulnerable system.\nUI:N - Exploitation only requires an already-established SMB1 mount, which in practice is persistent (fstab/autofs/systemd, embedded and industrial NAS deployments); a compromised or malicious server then attacks at a time of its choosing with no action by any local user.\nS:U - The use-after-free corrupts kernel heap objects within the same kernel security authority as the vulnerable code. No VM, IOMMU, or sandbox boundary is crossed.\nC:H - Use-after-free on `cifs_ses`/`cifs_tcon` structures lets the attacker reclaim the freed slab object with controlled content and have the kernel dereference and act on it, yielding a kernel-memory disclosure primitive. Session objects also hold credential material (auth keys, passwords), making leakage of highly sensitive data plausible.\nI:H - The UAF permits heap grooming so that attacker-shaped data occupies the freed session/tcon memory that is then written through and used for list and file-handle operations, giving a write/control-flow-hijack primitive. Per kernel CVSS guidance, memory corruption exploitable this way is scored High.\nA:H - Dereferencing freed session/tcon memory in the cifs demultiplex kernel thread readily produces an oops or panic, and the attacker can repeat it at will. Any kernel crash is High availability impact."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T11:30:27.234Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/494c91e1e9413b407d12166a61b84200d4d54fac"
        },
        {
          "url": "https://git.kernel.org/stable/c/0a15ba88a32fa7a516aff7ffd27befed5334dff2"
        },
        {
          "url": "https://git.kernel.org/stable/c/16d58c6a7db5050b9638669084b63fc05f951825"
        },
        {
          "url": "https://git.kernel.org/stable/c/69ccf040acddf33a3a85ec0f6b45ef84b0f7ec29"
        }
      ],
      "title": "smb: client: fix potential UAF in is_valid_oplock_break()",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2024-35863",
    "datePublished": "2024-05-19T08:34:22.114Z",
    "dateReserved": "2024-05-17T13:50:33.107Z",
    "dateUpdated": "2026-08-05T11:30:27.234Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "vulnrichment": {
      "containers": "{\"adp\": [{\"title\": \"CVE Program Container\", \"references\": [{\"url\": \"https://git.kernel.org/stable/c/494c91e1e9413b407d12166a61b84200d4d54fac\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/0a15ba88a32fa7a516aff7ffd27befed5334dff2\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/16d58c6a7db5050b9638669084b63fc05f951825\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/69ccf040acddf33a3a85ec0f6b45ef84b0f7ec29\", \"tags\": [\"x_transferred\"]}], \"providerMetadata\": {\"orgId\": \"af854a3a-2127-422b-91ae-364da2661108\", \"shortName\": \"CVE\", \"dateUpdated\": \"2024-08-02T03:21:48.533Z\"}}, {\"title\": \"CISA ADP Vulnrichment\", \"metrics\": [{\"other\": {\"type\": \"ssvc\", \"content\": {\"id\": \"CVE-2024-35863\", \"role\": \"CISA Coordinator\", \"options\": [{\"Exploitation\": \"none\"}, {\"Automatable\": \"no\"}, {\"Technical Impact\": \"partial\"}], \"version\": \"2.0.3\", \"timestamp\": \"2024-09-10T15:41:24.364295Z\"}}}], \"providerMetadata\": {\"orgId\": \"134c704f-9b21-4f2e-91b3-4a467353bcc0\", \"shortName\": \"CISA-ADP\", \"dateUpdated\": \"2024-09-11T12:42:15.910Z\"}}], \"cna\": {\"title\": \"smb: client: fix potential UAF in is_valid_oplock_break()\", \"metrics\": [{\"cvssV3_1\": {\"version\": \"3.1\", \"baseScore\": 9.8, \"baseSeverity\": \"CRITICAL\", \"vectorString\": \"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\"}, \"scenarios\": [{\"lang\": \"en\", \"value\": \"AV:N - The vulnerable walk is executed by the cifs demultiplex kernel thread directly on an unsolicited SMB1 LOCKING_ANDX frame read off the TCP/445 socket, so it is driven entirely by data from a remote SMB peer. A malicious/compromised file server, or an off-path/MITM injector on the unsigned SMB1 stream, reaches it over the network.\\nAC:L - The attacker controls both sides of the race: it can force repeated session teardowns (DFS referrals/failover, forced reconnects, multiuser tlink expiry) and can hold the SES_EXITING window open arbitrarily long by stalling the blocking SMB LOGOFF reply that `__cifs_put_smb_ses()` waits on before unlinking and freeing the session, while flooding oplock-break frames. Attempts are unlimited and require no condition outside the attacker\u0027s influence.\\nPR:N - No credentials or privileges on the victim client are needed \\u2014 the oplock-break frame is dispatched with no UID/session lookup and no signature validation, so any peer able to put bytes on the client\u0027s SMB connection triggers the walk. The attacking entity is the server side of an existing mount, which holds no privilege on the vulnerable system.\\nUI:N - Exploitation only requires an already-established SMB1 mount, which in practice is persistent (fstab/autofs/systemd, embedded and industrial NAS deployments); a compromised or malicious server then attacks at a time of its choosing with no action by any local user.\\nS:U - The use-after-free corrupts kernel heap objects within the same kernel security authority as the vulnerable code. No VM, IOMMU, or sandbox boundary is crossed.\\nC:H - Use-after-free on `cifs_ses`/`cifs_tcon` structures lets the attacker reclaim the freed slab object with controlled content and have the kernel dereference and act on it, yielding a kernel-memory disclosure primitive. Session objects also hold credential material (auth keys, passwords), making leakage of highly sensitive data plausible.\\nI:H - The UAF permits heap grooming so that attacker-shaped data occupies the freed session/tcon memory that is then written through and used for list and file-handle operations, giving a write/control-flow-hijack primitive. Per kernel CVSS guidance, memory corruption exploitable this way is scored High.\\nA:H - Dereferencing freed session/tcon memory in the cifs demultiplex kernel thread readily produces an oops or panic, and the attacker can repeat it at will. Any kernel crash is High availability impact.\"}]}], \"affected\": [{\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"7f48558e6489d032b1584b0cc9ac4bb11072c034\", \"lessThan\": \"494c91e1e9413b407d12166a61b84200d4d54fac\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"7f48558e6489d032b1584b0cc9ac4bb11072c034\", \"lessThan\": \"0a15ba88a32fa7a516aff7ffd27befed5334dff2\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"7f48558e6489d032b1584b0cc9ac4bb11072c034\", \"lessThan\": \"16d58c6a7db5050b9638669084b63fc05f951825\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"7f48558e6489d032b1584b0cc9ac4bb11072c034\", \"lessThan\": \"69ccf040acddf33a3a85ec0f6b45ef84b0f7ec29\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"a67172a013953664b1dad03c648200c70b90506c\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"3.12.48\", \"lessThan\": \"3.13\", \"versionType\": \"semver\"}], \"programFiles\": [\"fs/smb/client/misc.c\"], \"defaultStatus\": \"unaffected\"}, {\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"3.13\"}, {\"status\": \"unaffected\", \"version\": \"0\", \"lessThan\": \"3.13\", \"versionType\": \"semver\"}, {\"status\": \"unaffected\", \"version\": \"6.1.85\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.1.*\"}, {\"status\": \"unaffected\", \"version\": \"6.6.26\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.6.*\"}, {\"status\": \"unaffected\", \"version\": \"6.8.5\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.8.*\"}, {\"status\": \"unaffected\", \"version\": \"6.9\", \"versionType\": \"original_commit_for_fix\", \"lessThanOrEqual\": \"*\"}], \"programFiles\": [\"fs/smb/client/misc.c\"], \"defaultStatus\": \"affected\"}], \"references\": [{\"url\": \"https://git.kernel.org/stable/c/494c91e1e9413b407d12166a61b84200d4d54fac\"}, {\"url\": \"https://git.kernel.org/stable/c/0a15ba88a32fa7a516aff7ffd27befed5334dff2\"}, {\"url\": \"https://git.kernel.org/stable/c/16d58c6a7db5050b9638669084b63fc05f951825\"}, {\"url\": \"https://git.kernel.org/stable/c/69ccf040acddf33a3a85ec0f6b45ef84b0f7ec29\"}], \"x_generator\": {\"engine\": \"bippy-1.2.0\"}, \"descriptions\": [{\"lang\": \"en\", \"value\": \"In the Linux kernel, the following vulnerability has been resolved:\\n\\nsmb: client: fix potential UAF in is_valid_oplock_break()\\n\\nSkip sessions that are being teared down (status == SES_EXITING) to\\navoid UAF.\"}], \"cpeApplicability\": [{\"nodes\": [{\"negate\": false, \"cpeMatch\": [{\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.1.85\", \"versionStartIncluding\": \"3.13\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.6.26\", \"versionStartIncluding\": \"3.13\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.8.5\", \"versionStartIncluding\": \"3.13\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.9\", \"versionStartIncluding\": \"3.13\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionStartIncluding\": \"3.12.48\"}], \"operator\": \"OR\"}]}], \"providerMetadata\": {\"orgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"shortName\": \"Linux\", \"dateUpdated\": \"2026-08-05T11:30:27.234Z\"}}}",
      "cveMetadata": "{\"cveId\": \"CVE-2024-35863\", \"state\": \"PUBLISHED\", \"dateUpdated\": \"2026-08-05T11:30:27.234Z\", \"dateReserved\": \"2024-05-17T13:50:33.107Z\", \"assignerOrgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"datePublished\": \"2024-05-19T08:34:22.114Z\", \"assignerShortName\": \"Linux\"}",
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }
  }
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…