CVE-2024-26980

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix slab-out-of-bounds in smb2_allocate_rsp_buf If ->ProtocolId is SMB2_TRANSFORM_PROTO_NUM, smb2 request size validation could be skipped. if request size is smaller than sizeof(struct smb2_query_info_req), slab-out-of-bounds read can happen in smb2_allocate_rsp_buf(). This patch allocate response buffer after decrypting transform request. smb3_decrypt_req() will validate transform request size and avoid slab-out-of-bound in smb2_allocate_rsp_buf().
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.9:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.9:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.9:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.9:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.9:rc5:*:*:*:*:*:*

History

08 Apr 2025, 18:45

Type Values Removed Values Added
References () https://git.kernel.org/stable/c/0977f89722eceba165700ea384f075143f012085 - () https://git.kernel.org/stable/c/0977f89722eceba165700ea384f075143f012085 - Patch
References () https://git.kernel.org/stable/c/3160d9734453a40db248487f8204830879c207f1 - () https://git.kernel.org/stable/c/3160d9734453a40db248487f8204830879c207f1 - Patch
References () https://git.kernel.org/stable/c/b80ba648714e6d790d69610cf14656be222d0248 - () https://git.kernel.org/stable/c/b80ba648714e6d790d69610cf14656be222d0248 - Patch
References () https://git.kernel.org/stable/c/c119f4ede3fa90a9463f50831761c28f989bfb20 - () https://git.kernel.org/stable/c/c119f4ede3fa90a9463f50831761c28f989bfb20 - Patch
References () https://git.kernel.org/stable/c/da21401372607c49972ea87a6edaafb36a17c325 - () https://git.kernel.org/stable/c/da21401372607c49972ea87a6edaafb36a17c325 - Patch
CWE CWE-125
First Time Linux linux Kernel
Linux
CPE cpe:2.3:o:linux:linux_kernel:6.9:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.9:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.9:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.9:rc5:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.9:rc2:*:*:*:*:*:*

21 Nov 2024, 09:03

Type Values Removed Values Added
References () https://git.kernel.org/stable/c/0977f89722eceba165700ea384f075143f012085 - () https://git.kernel.org/stable/c/0977f89722eceba165700ea384f075143f012085 -
References () https://git.kernel.org/stable/c/3160d9734453a40db248487f8204830879c207f1 - () https://git.kernel.org/stable/c/3160d9734453a40db248487f8204830879c207f1 -
References () https://git.kernel.org/stable/c/b80ba648714e6d790d69610cf14656be222d0248 - () https://git.kernel.org/stable/c/b80ba648714e6d790d69610cf14656be222d0248 -
References () https://git.kernel.org/stable/c/c119f4ede3fa90a9463f50831761c28f989bfb20 - () https://git.kernel.org/stable/c/c119f4ede3fa90a9463f50831761c28f989bfb20 -
References () https://git.kernel.org/stable/c/da21401372607c49972ea87a6edaafb36a17c325 - () https://git.kernel.org/stable/c/da21401372607c49972ea87a6edaafb36a17c325 -

06 Nov 2024, 16:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5

17 May 2024, 11:15

Type Values Removed Values Added
References
  • () https://git.kernel.org/stable/c/da21401372607c49972ea87a6edaafb36a17c325 -

13 May 2024, 08:15

Type Values Removed Values Added
References
  • {'url': 'https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4EZ6PJW7VOZ224TD7N4JZNU6KV32ZJ53/', 'source': '416baaa9-dc9f-4396-8d5f-8c081fb06d67'}
  • {'url': 'https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DAMSOZXJEPUOXW33WZYWCVAY7Z5S7OOY/', 'source': '416baaa9-dc9f-4396-8d5f-8c081fb06d67'}
  • {'url': 'https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GCBZZEC7L7KTWWAS2NLJK6SO3IZIL4WW/', 'source': '416baaa9-dc9f-4396-8d5f-8c081fb06d67'}

03 May 2024, 03:16

Type Values Removed Values Added
References
  • () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4EZ6PJW7VOZ224TD7N4JZNU6KV32ZJ53/ -
  • () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DAMSOZXJEPUOXW33WZYWCVAY7Z5S7OOY/ -
  • () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GCBZZEC7L7KTWWAS2NLJK6SO3IZIL4WW/ -
Summary
  • (es) En el kernel de Linux, se resolvió la siguiente vulnerabilidad: ksmbd: corrige slab-out-of-bounds en smb2_allocate_rsp_buf Si ->ProtocolId es SMB2_TRANSFORM_PROTO_NUM, se podría omitir la validación del tamaño de la solicitud smb2. Si el tamaño de la solicitud es menor que sizeof (struct smb2_query_info_req), la lectura de losa fuera de los límites puede ocurrir en smb2_allocate_rsp_buf(). Este parche asigna un búfer de respuesta después de descifrar la solicitud de transformación. smb3_decrypt_req() validará el tamaño de la solicitud de transformación y evitará la losa fuera de los límites en smb2_allocate_rsp_buf().

01 May 2024, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-01 06:15

Updated : 2025-04-08 18:45


NVD link : CVE-2024-26980

Mitre link : CVE-2024-26980

CVE.ORG link : CVE-2024-26980


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-125

Out-of-bounds Read