CVE-2024-22705

CVSS v3.1 7.8 (High)
78% Progress
EPSS 0.04 % (10th)
0.04% Progress
Affected Products 1
Advisories 5

An issue was discovered in ksmbd in the Linux kernel before 6.6.10. smb2_get_data_area_len in fs/smb/server/smb2misc.c can cause an smb_strndup_from_utf16 out-of-bounds access because the relationship between Name data and CreateContexts data is mishandled.

Weaknesses
CWE-125
Out-of-bounds Read
CVE Status
PUBLISHED
CNA
MITRE
Published Date
2024-01-23 11:15:09
(7 months ago)
Updated Date
2024-01-29 17:39:39
(7 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Linux Kernel prior 6.6.10 version cpe:2.3:o:linux:linux_kernel < 6.6.10
  Linux Kernel 6.7 Rc1 cpe:2.3:o:linux:linux_kernel:6.7:rc1
  Linux Kernel 6.7 Rc2 cpe:2.3:o:linux:linux_kernel:6.7:rc2
  Linux Kernel 6.7 Rc3 cpe:2.3:o:linux:linux_kernel:6.7:rc3
  Linux Kernel 6.7 Rc4 cpe:2.3:o:linux:linux_kernel:6.7:rc4
  Linux Kernel 6.7 Rc5 cpe:2.3:o:linux:linux_kernel:6.7:rc5
  Linux Kernel 6.7 Rc6 cpe:2.3:o:linux:linux_kernel:6.7:rc6
  Linux Kernel 6.7 Rc7 cpe:2.3:o:linux:linux_kernel:6.7:rc7
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...