NA

CVE-2024-22705

Published: 23/01/2024 Updated: 29/01/2024
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 0

Vulnerability Summary

An issue exists in ksmbd in the Linux kernel prior to 6.6.10. smb2_get_data_area_len in fs/smb/server/smb2misc.c can cause an smb_strndup_from_utf16 out-of-bounds access because the relationship between Name data and CreateContexts data is mishandled.

Vulnerable Product Search on Vulmon Subscribe to Product

linux linux kernel 6.7

linux linux kernel

Vendor Advisories

Description<!---->A vulnerability was found in ksmbd in the Linux kernel's smb2_get_data_area_len in fs/smb/server/smb2misc This flaw allows an attacker to cause an smb_strndup_from_utf16 out-of-bounds access due to mishandling the relationship between Name data and CreateContexts dataA vulnerability was found in ksmbd in the Linux kernel's smb2_ ...