CVE-2024-35865
The Linux kernel SMB client contained a use‑after‑free vulnerability (CVE-2024-35865) that could be exploited remotely. The flaw was fixed by ensuring sessions marked as exiting are skipped during oplock break checks. Applying the kernel patch that addresses this issue removes the risk.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Linux kernel users, particularly those running affected versions.
Real-world impact
An attacker could achieve remote code execution with high impact on confidentiality, integrity, and availability.
Why this severity
CVSS v3.1 base score 9.8 (Critical) due to network‑adjacent attack vector, low complexity, no privileges or user interaction required, and high impact on all three security properties.
What to do about it
- 011. Obtain the latest Linux kernel update that includes the fix for CVE-2024-35865 (consult your distribution’s security advisory).
- 022. Install the kernel update using your system’s normal update mechanism.
- 033. Reboot the system to load the patched kernel.
NVD-referenced vendor advisory
Timeline
- May 19, 2024 · May 19, 2024PublishedDisclosed and added to the National Vulnerability Database.
- Aug 4, 2026 · 2d agoAdvisory updatedThe NVD record was last revised.
- Aug 5, 2026 · 1d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.