CVE-2024-35999: smb3: missing lock when picking channel
In the Linux kernel, the following vulnerability has been resolved:
smb3: missing lock when picking channel
Coverity spotted a place where we should have been holding the channel lock when accessing the ses channel index.
Addresses-Coverity: 1582039 ("Data race condition (MISSINGLOCK)")
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.25-1Fixed in 6.12.27-1
Event History
Frequently Asked Questions
What is the severity of CVE-2024-35999?
The severity of CVE-2024-35999 is critical due to the potential for a data race condition.
How do I fix CVE-2024-35999?
To fix CVE-2024-35999, upgrade to the recommended versions of the Linux kernel: 6.1.123-1, 6.1.128-1, 6.12.12-1, or 6.12.16-1.
Which Linux kernel versions are vulnerable to CVE-2024-35999?
Linux kernel versions up to 5.10.234-1 are vulnerable to CVE-2024-35999.
What component is affected by CVE-2024-35999?
CVE-2024-35999 affects the SMB3 protocol implementation in the Linux kernel.
Is CVE-2024-35999 a local or remote vulnerability?
CVE-2024-35999 is considered a local vulnerability as it impacts the kernel's operation on the host system.