CVE-2024-26811: ksmbd: validate payload size in ipc response
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: validate payload size in ipc response
If installing malicious ksmbd-tools, ksmbd.mountd can return invalid ipc response to ksmbd kernel server. ksmbd should validate payload size of ipc response from ksmbd.mountd to avoid memory overrun or slab-out-of-bounds. This patch validate 3 ipc response that has payload.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.25-1Fixed in 6.12.27-1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.6.82.1-1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 5.15.176.3-3 - Upgrade
Upgrade
Linux kernelto a version that resolves this vulnerability.Patch ksmbd: validate payload size in ipc response
Event History
Frequently Asked Questions
What is the severity of CVE-2024-26811?
CVE-2024-26811 has a medium severity rating due to its impact on the Linux kernel's ipc response validation.
How do I fix CVE-2024-26811?
To fix CVE-2024-26811, update the Linux kernel to a version that includes the security patch, such as 5.10.223-1, 5.10.226-1, 6.1.123-1, 6.1.128-1, 6.12.12-1, or 6.12.13-1.
What products are affected by CVE-2024-26811?
CVE-2024-26811 affects certain versions of the Linux kernel, specifically those prior to the patched versions mentioned.
What could happen if CVE-2024-26811 is exploited?
If exploited, CVE-2024-26811 could allow a malicious actor to manipulate ipc responses from ksmbd, potentially leading to further attacks.
Is there a workaround for CVE-2024-26811?
There is no specific workaround for CVE-2024-26811; the recommended action is to apply the security patches as soon as possible.