CVE-2024-35861
A vulnerability in the Linux kernel's SMB client component could lead to a 'use-after-free' error. This occurs when the system attempts to use memory that has already been released, potentially causing instability or allowing for unauthorized actions.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Users running Linux kernel version 6.9 or affected versions of the Linux kernel using the SMB client.
Real-world impact
An attacker could potentially exploit this flaw to cause a system crash or execute arbitrary code on the affected machine.
Why this severity
This is rated as critical because the vulnerability can be exploited remotely over a network without requiring any user interaction or special privileges, and it can lead to a total loss of confidentiality, integrity, and availability.
What to do about it
- 01Update the Linux kernel to a version that includes the fix for cifs_signal_cifsd_for_reconnect().
NVD-referenced vendor advisory
Timeline
- May 19, 2024 · May 19, 2024PublishedDisclosed and added to the National Vulnerability Database.
- Aug 4, 2026 · 2d agoAdvisory updatedThe NVD record was last revised.
- Aug 5, 2026 · 1d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.