CVE-2024-26811
A vulnerability in the Linux kernel's ksmbd module allows for memory errors when processing responses from malicious tools. This occurs because the system fails to properly validate the size of data received during communication.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Users running Linux kernel version 6.9 that utilize the ksmbd module.
Real-world impact
An attacker using malicious tools could trigger a memory overrun or a slab-out-of-bounds error, potentially leading to system instability or unauthorized code execution.
Why this severity
This is rated as critical because the vulnerability can be exploited remotely without any user interaction or authentication, and it can lead to a total loss of confidentiality, integrity, and availability.
What to do about it
- 01Apply the patch that validates the payload size of IPC responses in the ksmbd kernel server.
NVD-referenced vendor advisory
Timeline
- Apr 8, 2024 · Apr 8, 2024PublishedDisclosed and added to the National Vulnerability Database.
- Aug 4, 2026 · 2d agoAdvisory updatedThe NVD record was last revised.
- Aug 5, 2026 · 22h agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- git.kernel.org/stable/c/51a6c2af9d20203dde…patch
- git.kernel.org/stable/c/76af689a45aa44714b…patch
- git.kernel.org/stable/c/88b7f1143b15b29ccc…patch
- git.kernel.org/stable/c/a637fabac554270a85…patch
- git.kernel.org/stable/c/a677ebd8ca2f2632cc…patch
- lists.fedoraproject.org/archives/list/package-annou…
- lists.fedoraproject.org/archives/list/package-annou…
- lists.fedoraproject.org/archives/list/package-annou…