CVE-2024-53177 (GCVE-0-2024-53177)
Vulnerability from cvelistv5
Published
2024-12-27 13:49
Modified
2026-08-05 11:44
Severity ?
Summary
In the Linux kernel, the following vulnerability has been resolved: smb: prevent use-after-free due to open_cached_dir error paths If open_cached_dir() encounters an error parsing the lease from the server, the error handling may race with receiving a lease break, resulting in open_cached_dir() freeing the cfid while the queued work is pending. Update open_cached_dir() to drop refs rather than directly freeing the cfid. Have cached_dir_lease_break(), cfids_laundromat_worker(), and invalidate_all_cached_dirs() clear has_lease immediately while still holding cfids->cfid_list_lock, and then use this to also simplify the reference counting in cfids_laundromat_worker() and invalidate_all_cached_dirs(). Fixes this KASAN splat (which manually injects an error and lease break in open_cached_dir()): ================================================================== BUG: KASAN: slab-use-after-free in smb2_cached_lease_break+0x27/0xb0 Read of size 8 at addr ffff88811cc24c10 by task kworker/3:1/65 CPU: 3 UID: 0 PID: 65 Comm: kworker/3:1 Not tainted 6.12.0-rc6-g255cf264e6e5-dirty #87 Hardware name: VMware, Inc. VMware Virtual Platform/440BX Desktop Reference Platform, BIOS 6.00 11/12/2020 Workqueue: cifsiod smb2_cached_lease_break Call Trace: <TASK> dump_stack_lvl+0x77/0xb0 print_report+0xce/0x660 kasan_report+0xd3/0x110 smb2_cached_lease_break+0x27/0xb0 process_one_work+0x50a/0xc50 worker_thread+0x2ba/0x530 kthread+0x17c/0x1c0 ret_from_fork+0x34/0x60 ret_from_fork_asm+0x1a/0x30 </TASK> Allocated by task 2464: kasan_save_stack+0x33/0x60 kasan_save_track+0x14/0x30 __kasan_kmalloc+0xaa/0xb0 open_cached_dir+0xa7d/0x1fb0 smb2_query_path_info+0x43c/0x6e0 cifs_get_fattr+0x346/0xf10 cifs_get_inode_info+0x157/0x210 cifs_revalidate_dentry_attr+0x2d1/0x460 cifs_getattr+0x173/0x470 vfs_statx_path+0x10f/0x160 vfs_statx+0xe9/0x150 vfs_fstatat+0x5e/0xc0 __do_sys_newfstatat+0x91/0xf0 do_syscall_64+0x95/0x1a0 entry_SYSCALL_64_after_hwframe+0x76/0x7e Freed by task 2464: kasan_save_stack+0x33/0x60 kasan_save_track+0x14/0x30 kasan_save_free_info+0x3b/0x60 __kasan_slab_free+0x51/0x70 kfree+0x174/0x520 open_cached_dir+0x97f/0x1fb0 smb2_query_path_info+0x43c/0x6e0 cifs_get_fattr+0x346/0xf10 cifs_get_inode_info+0x157/0x210 cifs_revalidate_dentry_attr+0x2d1/0x460 cifs_getattr+0x173/0x470 vfs_statx_path+0x10f/0x160 vfs_statx+0xe9/0x150 vfs_fstatat+0x5e/0xc0 __do_sys_newfstatat+0x91/0xf0 do_syscall_64+0x95/0x1a0 entry_SYSCALL_64_after_hwframe+0x76/0x7e Last potentially related work creation: kasan_save_stack+0x33/0x60 __kasan_record_aux_stack+0xad/0xc0 insert_work+0x32/0x100 __queue_work+0x5c9/0x870 queue_work_on+0x82/0x90 open_cached_dir+0x1369/0x1fb0 smb2_query_path_info+0x43c/0x6e0 cifs_get_fattr+0x346/0xf10 cifs_get_inode_info+0x157/0x210 cifs_revalidate_dentry_attr+0x2d1/0x460 cifs_getattr+0x173/0x470 vfs_statx_path+0x10f/0x160 vfs_statx+0xe9/0x150 vfs_fstatat+0x5e/0xc0 __do_sys_newfstatat+0x91/0xf0 do_syscall_64+0x95/0x1a0 entry_SYSCALL_64_after_hwframe+0x76/0x7e The buggy address belongs to the object at ffff88811cc24c00 which belongs to the cache kmalloc-1k of size 1024 The buggy address is located 16 bytes inside of freed 1024-byte region [ffff88811cc24c00, ffff88811cc25000)
Impacted products
Vendor Product Version
Linux Linux Version: 93877b9afc2994c89362007aac480a7b150f386f
Version: 5c86919455c1edec99ebd3338ad213b59271a71b
Version: 5c86919455c1edec99ebd3338ad213b59271a71b
Version: 5c86919455c1edec99ebd3338ad213b59271a71b
Version: 6db94d08359c43f2c8fe372811cdee04564a41b9
Version: 6.6.3   
Version: 6.5.13   
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "cvssV3_1": {
              "attackComplexity": "LOW",
              "attackVector": "LOCAL",
              "availabilityImpact": "HIGH",
              "baseScore": 7.8,
              "baseSeverity": "HIGH",
              "confidentialityImpact": "HIGH",
              "integrityImpact": "HIGH",
              "privilegesRequired": "LOW",
              "scope": "UNCHANGED",
              "userInteraction": "NONE",
              "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
              "version": "3.1"
            }
          },
          {
            "other": {
              "content": {
                "id": "CVE-2024-53177",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "total"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2025-02-11T15:43:30.968681Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "problemTypes": [
          {
            "descriptions": [
              {
                "cweId": "CWE-416",
                "description": "CWE-416 Use After Free",
                "lang": "en",
                "type": "CWE"
              }
            ]
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2025-02-11T15:45:26.716Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "fs/smb/client/cached_dir.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "791f833053578b9fd24252ebb7162a61bc3f805b",
              "status": "affected",
              "version": "93877b9afc2994c89362007aac480a7b150f386f",
              "versionType": "git"
            },
            {
              "lessThan": "97e2afcac0bebfef6a5360f4267ce4c44507b845",
              "status": "affected",
              "version": "5c86919455c1edec99ebd3338ad213b59271a71b",
              "versionType": "git"
            },
            {
              "lessThan": "47655a12c6b1bca8fa230085eab2e85a076932b7",
              "status": "affected",
              "version": "5c86919455c1edec99ebd3338ad213b59271a71b",
              "versionType": "git"
            },
            {
              "lessThan": "a9685b409a03b73d2980bbfa53eb47555802d0a9",
              "status": "affected",
              "version": "5c86919455c1edec99ebd3338ad213b59271a71b",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "6db94d08359c43f2c8fe372811cdee04564a41b9",
              "versionType": "git"
            },
            {
              "lessThan": "6.6.64",
              "status": "affected",
              "version": "6.6.3",
              "versionType": "semver"
            },
            {
              "lessThan": "6.6",
              "status": "affected",
              "version": "6.5.13",
              "versionType": "semver"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "fs/smb/client/cached_dir.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.7"
            },
            {
              "lessThan": "6.7",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.64",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.11.*",
              "status": "unaffected",
              "version": "6.11.11",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.12.*",
              "status": "unaffected",
              "version": "6.12.2",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "6.13",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.64",
                  "versionStartIncluding": "6.6.3",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.11.11",
                  "versionStartIncluding": "6.7",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12.2",
                  "versionStartIncluding": "6.7",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.13",
                  "versionStartIncluding": "6.7",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionStartIncluding": "6.5.13",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: prevent use-after-free due to open_cached_dir error paths\n\nIf open_cached_dir() encounters an error parsing the lease from the\nserver, the error handling may race with receiving a lease break,\nresulting in open_cached_dir() freeing the cfid while the queued work is\npending.\n\nUpdate open_cached_dir() to drop refs rather than directly freeing the\ncfid.\n\nHave cached_dir_lease_break(), cfids_laundromat_worker(), and\ninvalidate_all_cached_dirs() clear has_lease immediately while still\nholding cfids-\u003ecfid_list_lock, and then use this to also simplify the\nreference counting in cfids_laundromat_worker() and\ninvalidate_all_cached_dirs().\n\nFixes this KASAN splat (which manually injects an error and lease break\nin open_cached_dir()):\n\n==================================================================\nBUG: KASAN: slab-use-after-free in smb2_cached_lease_break+0x27/0xb0\nRead of size 8 at addr ffff88811cc24c10 by task kworker/3:1/65\n\nCPU: 3 UID: 0 PID: 65 Comm: kworker/3:1 Not tainted 6.12.0-rc6-g255cf264e6e5-dirty #87\nHardware name: VMware, Inc. VMware Virtual Platform/440BX Desktop Reference Platform, BIOS 6.00 11/12/2020\nWorkqueue: cifsiod smb2_cached_lease_break\nCall Trace:\n \u003cTASK\u003e\n dump_stack_lvl+0x77/0xb0\n print_report+0xce/0x660\n kasan_report+0xd3/0x110\n smb2_cached_lease_break+0x27/0xb0\n process_one_work+0x50a/0xc50\n worker_thread+0x2ba/0x530\n kthread+0x17c/0x1c0\n ret_from_fork+0x34/0x60\n ret_from_fork_asm+0x1a/0x30\n \u003c/TASK\u003e\n\nAllocated by task 2464:\n kasan_save_stack+0x33/0x60\n kasan_save_track+0x14/0x30\n __kasan_kmalloc+0xaa/0xb0\n open_cached_dir+0xa7d/0x1fb0\n smb2_query_path_info+0x43c/0x6e0\n cifs_get_fattr+0x346/0xf10\n cifs_get_inode_info+0x157/0x210\n cifs_revalidate_dentry_attr+0x2d1/0x460\n cifs_getattr+0x173/0x470\n vfs_statx_path+0x10f/0x160\n vfs_statx+0xe9/0x150\n vfs_fstatat+0x5e/0xc0\n __do_sys_newfstatat+0x91/0xf0\n do_syscall_64+0x95/0x1a0\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\nFreed by task 2464:\n kasan_save_stack+0x33/0x60\n kasan_save_track+0x14/0x30\n kasan_save_free_info+0x3b/0x60\n __kasan_slab_free+0x51/0x70\n kfree+0x174/0x520\n open_cached_dir+0x97f/0x1fb0\n smb2_query_path_info+0x43c/0x6e0\n cifs_get_fattr+0x346/0xf10\n cifs_get_inode_info+0x157/0x210\n cifs_revalidate_dentry_attr+0x2d1/0x460\n cifs_getattr+0x173/0x470\n vfs_statx_path+0x10f/0x160\n vfs_statx+0xe9/0x150\n vfs_fstatat+0x5e/0xc0\n __do_sys_newfstatat+0x91/0xf0\n do_syscall_64+0x95/0x1a0\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\nLast potentially related work creation:\n kasan_save_stack+0x33/0x60\n __kasan_record_aux_stack+0xad/0xc0\n insert_work+0x32/0x100\n __queue_work+0x5c9/0x870\n queue_work_on+0x82/0x90\n open_cached_dir+0x1369/0x1fb0\n smb2_query_path_info+0x43c/0x6e0\n cifs_get_fattr+0x346/0xf10\n cifs_get_inode_info+0x157/0x210\n cifs_revalidate_dentry_attr+0x2d1/0x460\n cifs_getattr+0x173/0x470\n vfs_statx_path+0x10f/0x160\n vfs_statx+0xe9/0x150\n vfs_fstatat+0x5e/0xc0\n __do_sys_newfstatat+0x91/0xf0\n do_syscall_64+0x95/0x1a0\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\nThe buggy address belongs to the object at ffff88811cc24c00\n which belongs to the cache kmalloc-1k of size 1024\nThe buggy address is located 16 bytes inside of\n freed 1024-byte region [ffff88811cc24c00, ffff88811cc25000)"
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:N - The UAF is driven entirely by data received from a remote SMB server over TCP/445 \u2014 a crafted SMB2 CREATE/QUERY_INFO response that forces the error path, plus an unsolicited SMB2 lease-break packet processed by the cifsd demultiplex thread. No local access to the victim is needed.\nAC:L - The malicious server controls both sides of the race: it makes the response fail parsing deterministically (short FILE_ALL_INFORMATION or a lease lacking READ caching) and it chooses exactly when to send the lease break, using the lease key the client disclosed in its own CREATE request. It gets unlimited retries via every directory access and every server-forced reconnect.\nPR:N - The attacker is the SMB server (or a MITM on an unsigned connection) and holds no privileges on the victim host; it is the authenticating party and can accept any credentials the client offers. The vulnerable code is reached automatically at tree connect (smb3_qfs_tcon \u2192 open_cached_dir) with no client-side account required.\nUI:N - Against an existing CIFS mount \u2014 the realistic case of an enterprise/cloud host mounting a file server that is compromised or MITM\u0027d, or an autofs/systemd mount \u2014 the server triggers the bug at will, including by forcing reconnects that re-enter open_cached_dir(). No victim action is required at exploitation time.\nS:U - The corruption and its consequences are confined to the kernel\u0027s own security authority; there is no VM, IOMMU, or sandbox boundary crossed.\nC:H - The freed kmalloc-1k cached_fid is subsequently read by smb2_cached_lease_break(), which dereferences cfid-\u003ecfids and later cfid-\u003edentry/cfid-\u003etcon; with heap spray this yields attacker-directed reads of kernel memory and leaks of kernel pointers.\nI:H - The stale reference produces a write into freed memory (atomic kref decrement) and, on reaching zero, list_del(\u0026cfid-\u003eentry) \u2014 a classic write-what-where unlink \u2014 plus dput() on a sprayed dentry, giving heap-spray-based arbitrary write and control-flow hijack potential.\nA:H - Even unweaponized, the use-after-free causes a spinlock acquisition and refcount manipulation on freed memory, reliably producing kernel oops/panic, and the server can retrigger it repeatedly."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T11:44:24.120Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/791f833053578b9fd24252ebb7162a61bc3f805b"
        },
        {
          "url": "https://git.kernel.org/stable/c/97e2afcac0bebfef6a5360f4267ce4c44507b845"
        },
        {
          "url": "https://git.kernel.org/stable/c/47655a12c6b1bca8fa230085eab2e85a076932b7"
        },
        {
          "url": "https://git.kernel.org/stable/c/a9685b409a03b73d2980bbfa53eb47555802d0a9"
        }
      ],
      "title": "smb: prevent use-after-free due to open_cached_dir error paths",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2024-53177",
    "datePublished": "2024-12-27T13:49:21.362Z",
    "dateReserved": "2024-11-19T17:17:25.007Z",
    "dateUpdated": "2026-08-05T11:44:24.120Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "vulnrichment": {
      "containers": "{\"adp\": [{\"title\": \"CISA ADP Vulnrichment\", \"metrics\": [{\"cvssV3_1\": {\"scope\": \"UNCHANGED\", \"version\": \"3.1\", \"baseScore\": 7.8, \"attackVector\": \"LOCAL\", \"baseSeverity\": \"HIGH\", \"vectorString\": \"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H\", \"integrityImpact\": \"HIGH\", \"userInteraction\": \"NONE\", \"attackComplexity\": \"LOW\", \"availabilityImpact\": \"HIGH\", \"privilegesRequired\": \"LOW\", \"confidentialityImpact\": \"HIGH\"}}, {\"other\": {\"type\": \"ssvc\", \"content\": {\"id\": \"CVE-2024-53177\", \"role\": \"CISA Coordinator\", \"options\": [{\"Exploitation\": \"none\"}, {\"Automatable\": \"no\"}, {\"Technical Impact\": \"total\"}], \"version\": \"2.0.3\", \"timestamp\": \"2025-02-11T15:43:30.968681Z\"}}}], \"problemTypes\": [{\"descriptions\": [{\"lang\": \"en\", \"type\": \"CWE\", \"cweId\": \"CWE-416\", \"description\": \"CWE-416 Use After Free\"}]}], \"providerMetadata\": {\"orgId\": \"134c704f-9b21-4f2e-91b3-4a467353bcc0\", \"shortName\": \"CISA-ADP\", \"dateUpdated\": \"2025-02-11T15:43:32.309Z\"}}], \"cna\": {\"title\": \"smb: prevent use-after-free due to open_cached_dir error paths\", \"affected\": [{\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"93877b9afc2994c89362007aac480a7b150f386f\", \"lessThan\": \"791f833053578b9fd24252ebb7162a61bc3f805b\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"5c86919455c1edec99ebd3338ad213b59271a71b\", \"lessThan\": \"97e2afcac0bebfef6a5360f4267ce4c44507b845\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"5c86919455c1edec99ebd3338ad213b59271a71b\", \"lessThan\": \"47655a12c6b1bca8fa230085eab2e85a076932b7\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"5c86919455c1edec99ebd3338ad213b59271a71b\", \"lessThan\": \"a9685b409a03b73d2980bbfa53eb47555802d0a9\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"6db94d08359c43f2c8fe372811cdee04564a41b9\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"6.6.3\", \"lessThan\": \"6.6.64\", \"versionType\": \"semver\"}, {\"status\": \"affected\", \"version\": \"6.5.13\", \"lessThan\": \"6.6\", \"versionType\": \"semver\"}], \"programFiles\": [\"fs/smb/client/cached_dir.c\"], \"defaultStatus\": \"unaffected\"}, {\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"6.7\"}, {\"status\": \"unaffected\", \"version\": \"0\", \"lessThan\": \"6.7\", \"versionType\": \"semver\"}, {\"status\": \"unaffected\", \"version\": \"6.6.64\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.6.*\"}, {\"status\": \"unaffected\", \"version\": \"6.11.11\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.11.*\"}, {\"status\": \"unaffected\", \"version\": \"6.12.2\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.12.*\"}, {\"status\": \"unaffected\", \"version\": \"6.13\", \"versionType\": \"original_commit_for_fix\", \"lessThanOrEqual\": \"*\"}], \"programFiles\": [\"fs/smb/client/cached_dir.c\"], \"defaultStatus\": \"affected\"}], \"references\": [{\"url\": \"https://git.kernel.org/stable/c/791f833053578b9fd24252ebb7162a61bc3f805b\"}, {\"url\": \"https://git.kernel.org/stable/c/97e2afcac0bebfef6a5360f4267ce4c44507b845\"}, {\"url\": \"https://git.kernel.org/stable/c/47655a12c6b1bca8fa230085eab2e85a076932b7\"}, {\"url\": \"https://git.kernel.org/stable/c/a9685b409a03b73d2980bbfa53eb47555802d0a9\"}], \"x_generator\": {\"engine\": \"bippy-1.2.0\"}, \"descriptions\": [{\"lang\": \"en\", \"value\": \"In the Linux kernel, the following vulnerability has been resolved:\\n\\nsmb: prevent use-after-free due to open_cached_dir error paths\\n\\nIf open_cached_dir() encounters an error parsing the lease from the\\nserver, the error handling may race with receiving a lease break,\\nresulting in open_cached_dir() freeing the cfid while the queued work is\\npending.\\n\\nUpdate open_cached_dir() to drop refs rather than directly freeing the\\ncfid.\\n\\nHave cached_dir_lease_break(), cfids_laundromat_worker(), and\\ninvalidate_all_cached_dirs() clear has_lease immediately while still\\nholding cfids-\u003ecfid_list_lock, and then use this to also simplify the\\nreference counting in cfids_laundromat_worker() and\\ninvalidate_all_cached_dirs().\\n\\nFixes this KASAN splat (which manually injects an error and lease break\\nin open_cached_dir()):\\n\\n==================================================================\\nBUG: KASAN: slab-use-after-free in smb2_cached_lease_break+0x27/0xb0\\nRead of size 8 at addr ffff88811cc24c10 by task kworker/3:1/65\\n\\nCPU: 3 UID: 0 PID: 65 Comm: kworker/3:1 Not tainted 6.12.0-rc6-g255cf264e6e5-dirty #87\\nHardware name: VMware, Inc. VMware Virtual Platform/440BX Desktop Reference Platform, BIOS 6.00 11/12/2020\\nWorkqueue: cifsiod smb2_cached_lease_break\\nCall Trace:\\n \u003cTASK\u003e\\n dump_stack_lvl+0x77/0xb0\\n print_report+0xce/0x660\\n kasan_report+0xd3/0x110\\n smb2_cached_lease_break+0x27/0xb0\\n process_one_work+0x50a/0xc50\\n worker_thread+0x2ba/0x530\\n kthread+0x17c/0x1c0\\n ret_from_fork+0x34/0x60\\n ret_from_fork_asm+0x1a/0x30\\n \u003c/TASK\u003e\\n\\nAllocated by task 2464:\\n kasan_save_stack+0x33/0x60\\n kasan_save_track+0x14/0x30\\n __kasan_kmalloc+0xaa/0xb0\\n open_cached_dir+0xa7d/0x1fb0\\n smb2_query_path_info+0x43c/0x6e0\\n cifs_get_fattr+0x346/0xf10\\n cifs_get_inode_info+0x157/0x210\\n cifs_revalidate_dentry_attr+0x2d1/0x460\\n cifs_getattr+0x173/0x470\\n vfs_statx_path+0x10f/0x160\\n vfs_statx+0xe9/0x150\\n vfs_fstatat+0x5e/0xc0\\n __do_sys_newfstatat+0x91/0xf0\\n do_syscall_64+0x95/0x1a0\\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\\n\\nFreed by task 2464:\\n kasan_save_stack+0x33/0x60\\n kasan_save_track+0x14/0x30\\n kasan_save_free_info+0x3b/0x60\\n __kasan_slab_free+0x51/0x70\\n kfree+0x174/0x520\\n open_cached_dir+0x97f/0x1fb0\\n smb2_query_path_info+0x43c/0x6e0\\n cifs_get_fattr+0x346/0xf10\\n cifs_get_inode_info+0x157/0x210\\n cifs_revalidate_dentry_attr+0x2d1/0x460\\n cifs_getattr+0x173/0x470\\n vfs_statx_path+0x10f/0x160\\n vfs_statx+0xe9/0x150\\n vfs_fstatat+0x5e/0xc0\\n __do_sys_newfstatat+0x91/0xf0\\n do_syscall_64+0x95/0x1a0\\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\\n\\nLast potentially related work creation:\\n kasan_save_stack+0x33/0x60\\n __kasan_record_aux_stack+0xad/0xc0\\n insert_work+0x32/0x100\\n __queue_work+0x5c9/0x870\\n queue_work_on+0x82/0x90\\n open_cached_dir+0x1369/0x1fb0\\n smb2_query_path_info+0x43c/0x6e0\\n cifs_get_fattr+0x346/0xf10\\n cifs_get_inode_info+0x157/0x210\\n cifs_revalidate_dentry_attr+0x2d1/0x460\\n cifs_getattr+0x173/0x470\\n vfs_statx_path+0x10f/0x160\\n vfs_statx+0xe9/0x150\\n vfs_fstatat+0x5e/0xc0\\n __do_sys_newfstatat+0x91/0xf0\\n do_syscall_64+0x95/0x1a0\\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\\n\\nThe buggy address belongs to the object at ffff88811cc24c00\\n which belongs to the cache kmalloc-1k of size 1024\\nThe buggy address is located 16 bytes inside of\\n freed 1024-byte region [ffff88811cc24c00, ffff88811cc25000)\"}], \"cpeApplicability\": [{\"nodes\": [{\"negate\": false, \"cpeMatch\": [{\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.6.64\", \"versionStartIncluding\": \"6.6.3\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.11.11\", \"versionStartIncluding\": \"6.7\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.12.2\", \"versionStartIncluding\": \"6.7\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.13\", \"versionStartIncluding\": \"6.7\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionStartIncluding\": \"6.5.13\"}], \"operator\": \"OR\"}]}], \"providerMetadata\": {\"orgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"shortName\": \"Linux\", \"dateUpdated\": \"2026-05-23T15:55:19.574Z\"}}}",
      "cveMetadata": "{\"cveId\": \"CVE-2024-53177\", \"state\": \"PUBLISHED\", \"dateUpdated\": \"2026-05-23T15:55:19.574Z\", \"dateReserved\": \"2024-11-19T17:17:25.007Z\", \"assignerOrgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"datePublished\": \"2024-12-27T13:49:21.362Z\", \"assignerShortName\": \"Linux\"}",
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }
  }
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…