CVE-2024-35862
A vulnerability in the Linux kernel's SMB client component could lead to a 'use-after-free' error. This occurs when the system tries to use memory that has already been released, potentially causing instability or security issues.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Users running Linux kernel version 6.9 or affected versions of the Linux kernel.
Real-world impact
An attacker could potentially exploit this flaw to cause a system crash or execute unauthorized code by manipulating network sessions.
Why this severity
The critical score reflects that this flaw can be exploited remotely over a network without requiring user interaction or special privileges, potentially impacting the confidentiality, integrity, and availability of the system.
What to do about it
- 01Upgrade the Linux kernel to a version that includes the fix for smb2_is_network_name_deleted().
NVD-referenced vendor advisory
Timeline
- May 19, 2024 · May 19, 2024PublishedDisclosed and added to the National Vulnerability Database.
- Aug 4, 2026 · 2d agoAdvisory updatedThe NVD record was last revised.
- Aug 5, 2026 · 1d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.