CVE-2024-50086
A flaw in the Linux kernel's ksmbd component allows for a 'user-after-free' error during the process of logging off or setting up SMB2 sessions. This occurs due to a race condition where the system attempts to use memory that has already been released.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Users running the Linux kernel, specifically versions including 6.12, that utilize the ksmbd module.
Real-world impact
An attacker could potentially exploit this memory error to cause system instability or execute unauthorized code by interfering with how the kernel manages network sessions.
Why this severity
This is rated as critical because the vulnerability can be exploited remotely over a network without requiring any user interaction or special privileges, potentially leading to a total loss of confidentiality, integrity, and availability.
What to do about it
- 01Update the Linux kernel to a version that includes the fix for ksmbd session management.
NVD-referenced vendor advisory
Timeline
- Oct 29, 2024 · Oct 29, 2024PublishedDisclosed and added to the National Vulnerability Database.
- Aug 4, 2026 · 2d agoAdvisory updatedThe NVD record was last revised.
- Aug 4, 2026 · 1d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.