Bugzilla – Bug 1220327
VUL-0: CVE-2024-26594: kernel: Linux Kernel ksmbd Mech Token Out-Of-Bounds Read Information Disclosure Vulnerability
Last modified: 2024-05-29 12:31:14 UTC
In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate mech token in session setup If client send invalid mech token in session setup request, ksmbd validate and make the error if it is invalid. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-26594 https://www.cve.org/CVERecord?id=CVE-2024-26594 https://git.kernel.org/stable/c/5e6dfec95833edc54c48605a98365a7325e5541e https://git.kernel.org/stable/c/6eb8015492bcc84e40646390e50a862b2c0529c9 https://git.kernel.org/stable/c/92e470163d96df8db6c4fa0f484e4a229edb903d https://git.kernel.org/stable/c/a2b21ef1ea4cf632d19b3a7cc4d4245b8e63202a https://git.kernel.org/stable/c/dd1de9268745f0eac83a430db7afc32cbd62e84b https://www.zerodayinitiative.com/advisories/ZDI-24-194/
KSMBD is only supported in Tumbleweed.
Fixing commit: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=92e470163d96df8db6c4fa0f484e4a229edb903d
All done, closing.