Back

HIGH

Kernel: ksmbd: smb2_open out-of-bounds read information disclosure vulnerability

Published Nov 14, 2024

Description

A flaw was found within the parsing of extended attributes in the kernel ksmbd module. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this to disclose sensitive information on affected installations of Linux. Only systems with ksmbd enabled are vulnerable to this CVE.

Affected products

Remediation

Red Hat statement

No Red Hat products are affected by this flaw, as the ksmbd code is not included in any shipped RHEL kernel release.

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner fedora
Published Nov 14, 2024
Updated Nov 14, 2024
Reserved Aug 21, 2023
CISA Vulnrichment
Updated Nov 14, 2024
NVD
Status Analyzed
Modified Oct 2, 2026
Red Hat
Severity Low
Public date Jun 10, 2024