CVE-2024-53186
A critical race condition in the Linux kernel's SMB server (ksmbd) can lead to a use‑after‑free, allowing attackers to read or write arbitrary memory. The flaw arises when a connection is freed while still being processed. The issue has been fixed in the kernel.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Linux kernel (ksmbd SMB server) – any system running a kernel version before the fix.
Real-world impact
An attacker could exploit the race to read or corrupt memory, potentially taking control of the system or causing a crash.
Why this severity
The CVSS score of 9.8 reflects the lack of authentication or UI requirement, the high impact on confidentiality, integrity, and availability, and the low attack complexity.
What to do about it
- 01Upgrade your Linux kernel to a version that includes the ksmbd fix.
- 02Reboot the system to load the new kernel.
NVD-referenced vendor advisory
Timeline
- Dec 27, 2024 · Dec 27, 2024PublishedDisclosed and added to the National Vulnerability Database.
- Aug 4, 2026 · 2d agoAdvisory updatedThe NVD record was last revised.
- Aug 4, 2026 · 1d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.