CVE-2024-22705: High severity Linux Linux kernel vulnerability
An issue was discovered in ksmbd in the Linux kernel before 6.6.10. smb2getdataarealen in fs/smb/server/smb2misc.c can cause an smbstrndupfromutf16 out-of-bounds access because the relationship between Name data and CreateContexts data is mishandled.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.25-1Fixed in 6.12.27-1 - Upgrade
Upgrade
linux kernel (ksmbd)to a version that resolves this vulnerability.Fixed in 6.6.10
Event History
Frequently Asked Questions
What is the severity of CVE-2024-22705?
CVE-2024-22705 has been classified with a severity level that indicates a potential out-of-bounds access vulnerability in the Linux kernel.
How do I fix CVE-2024-22705?
To fix CVE-2024-22705, you need to update your Linux kernel to version 6.6.10 or later, or apply any available patches that address this vulnerability.
Which Linux kernel versions are affected by CVE-2024-22705?
CVE-2024-22705 affects Linux kernel versions prior to 6.6.10, including various release candidates of version 6.7.
What components are involved in the issue described by CVE-2024-22705?
The issue in CVE-2024-22705 involves the ksmbd component within the Linux kernel, specifically related to smb2_get_data_area_len and its handling of Name and CreateContexts data.
Is my system vulnerable if I am running an older version of the Linux kernel?
Yes, if you are running an older version of the Linux kernel prior to 6.6.10, your system is vulnerable to CVE-2024-22705 and should be updated immediately.