{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2024-26592",
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "state": "PUBLISHED",
        "assignerShortName": "Linux",
        "dateReserved": "2024-02-19T14:20:24.126Z",
        "datePublished": "2024-02-22T16:21:44.626Z",
        "dateUpdated": "2026-08-05T11:26:07.571Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
                "shortName": "Linux",
                "dateUpdated": "2026-08-05T11:26:07.571Z"
            },
            "descriptions": [
                {
                    "lang": "en",
                    "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix UAF issue in ksmbd_tcp_new_connection()\n\nThe race is between the handling of a new TCP connection and\nits disconnection. It leads to UAF on `struct tcp_transport` in\nksmbd_tcp_new_connection() function."
                }
            ],
            "metrics": [
                {
                    "cvssV3_1": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL"
                    },
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "AV:N - ksmbd is the in-kernel SMB server listening on TCP port 445; the vulnerable code is `ksmbd_tcp_new_connection()`, invoked directly from `kernel_accept()` on a remote peer's TCP connection. No local access to the target is required.\nAC:L - The attacker controls both sides of the race — connecting spawns the handler kthread, and immediately closing (FIN, or RST via SO_LINGER{1,0}) drives that kthread down the shortest possible path to `free_transport()`/`kfree(t)` while the acceptor still has to perform its stale store. Attempts are unauthenticated, cost one TCP handshake each, and can be repeated thousands of times per second while flooding the single acceptor kthread to force preemption.\nPR:N - The path runs at TCP accept time, before SMB2 NEGOTIATE and SESSION_SETUP and before any NTLMSSP/Kerberos credential is processed; no share, account, or guest access is needed. Merely completing a TCP handshake to port 445 reaches the vulnerable code.\nUI:N - Exploitation requires only that the attacker connect to and disconnect from the ksmbd port; no action by any local user or administrator is involved.\nS:U - The corrupted memory and the resulting code execution are within the kernel's own security authority — a standard in-kernel use-after-free with no crossing of a VM, IOMMU, or sandbox boundary.\nC:H - The freed `struct tcp_transport` lives in the general kmalloc-64 cache, and the attacker can reclaim the slot with sprayed objects (including via parallel connections) before the stale write and readback occur; corrupting a pointer field of a reclaimed victim object yields a read primitive over kernel memory, disclosing credentials, keys, and SMB share data.\nI:H - The bug is a use-after-free *write* — a live `task_struct *` is stored at a fixed offset 16 into a freed general-purpose slab object, overwriting whatever object reclaims that slot. Corrupting a pointer/list field of a sprayed victim object is a classic route to an arbitrary write and control-flow hijack in ring 0.\nA:H - Even without successful heap grooming, the stale write and subsequent `IS_ERR()` read on freed slab memory corrupt unrelated kernel objects, producing oopses and panics (KASAN reports a slab-use-after-free write). An unauthenticated attacker can retry the connect/disconnect race indefinitely until the machine crashes."
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "unaffected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "fs/smb/server/connection.c",
                        "fs/smb/server/connection.h",
                        "fs/smb/server/transport_rdma.c",
                        "fs/smb/server/transport_tcp.c"
                    ],
                    "versions": [
                        {
                            "version": "a848c4f15ab6d5d405dbee7de5da71839b2bf35e",
                            "lessThan": "999daf367b924fdf14e9d83e034ee0f86bc17ec6",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "a848c4f15ab6d5d405dbee7de5da71839b2bf35e",
                            "lessThan": "380965e48e9c32ee4263c023e1d830ea7e462ed1",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "a848c4f15ab6d5d405dbee7de5da71839b2bf35e",
                            "lessThan": "24290ba94cd0136e417283b0dbf8fcdabcf62111",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "a848c4f15ab6d5d405dbee7de5da71839b2bf35e",
                            "lessThan": "69d54650b751532d1e1613a4fb433e591aeef126",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "a848c4f15ab6d5d405dbee7de5da71839b2bf35e",
                            "lessThan": "38d20c62903d669693a1869aa68c4dd5674e2544",
                            "status": "affected",
                            "versionType": "git"
                        }
                    ]
                },
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "affected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "fs/smb/server/connection.c",
                        "fs/smb/server/connection.h",
                        "fs/smb/server/transport_rdma.c",
                        "fs/smb/server/transport_tcp.c"
                    ],
                    "versions": [
                        {
                            "version": "5.15",
                            "status": "affected"
                        },
                        {
                            "version": "0",
                            "lessThan": "5.15",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "5.15.149",
                            "lessThanOrEqual": "5.15.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.1.75",
                            "lessThanOrEqual": "6.1.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.6.14",
                            "lessThanOrEqual": "6.6.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.7.2",
                            "lessThanOrEqual": "6.7.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.8",
                            "lessThanOrEqual": "*",
                            "status": "unaffected",
                            "versionType": "original_commit_for_fix"
                        }
                    ]
                }
            ],
            "cpeApplicability": [
                {
                    "nodes": [
                        {
                            "operator": "OR",
                            "negate": false,
                            "cpeMatch": [
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.15",
                                    "versionEndExcluding": "5.15.149"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.15",
                                    "versionEndExcluding": "6.1.75"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.15",
                                    "versionEndExcluding": "6.6.14"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.15",
                                    "versionEndExcluding": "6.7.2"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.15",
                                    "versionEndExcluding": "6.8"
                                }
                            ]
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://git.kernel.org/stable/c/999daf367b924fdf14e9d83e034ee0f86bc17ec6"
                },
                {
                    "url": "https://git.kernel.org/stable/c/380965e48e9c32ee4263c023e1d830ea7e462ed1"
                },
                {
                    "url": "https://git.kernel.org/stable/c/24290ba94cd0136e417283b0dbf8fcdabcf62111"
                },
                {
                    "url": "https://git.kernel.org/stable/c/69d54650b751532d1e1613a4fb433e591aeef126"
                },
                {
                    "url": "https://git.kernel.org/stable/c/38d20c62903d669693a1869aa68c4dd5674e2544"
                }
            ],
            "title": "ksmbd: fix UAF issue in ksmbd_tcp_new_connection()",
            "x_generator": {
                "engine": "bippy-1.2.0"
            }
        },
        "adp": [
            {
                "providerMetadata": {
                    "orgId": "af854a3a-2127-422b-91ae-364da2661108",
                    "shortName": "CVE",
                    "dateUpdated": "2024-08-02T00:07:19.957Z"
                },
                "title": "CVE Program Container",
                "references": [
                    {
                        "url": "https://git.kernel.org/stable/c/999daf367b924fdf14e9d83e034ee0f86bc17ec6",
                        "tags": [
                            "x_transferred"
                        ]
                    },
                    {
                        "url": "https://git.kernel.org/stable/c/380965e48e9c32ee4263c023e1d830ea7e462ed1",
                        "tags": [
                            "x_transferred"
                        ]
                    },
                    {
                        "url": "https://git.kernel.org/stable/c/24290ba94cd0136e417283b0dbf8fcdabcf62111",
                        "tags": [
                            "x_transferred"
                        ]
                    },
                    {
                        "url": "https://git.kernel.org/stable/c/69d54650b751532d1e1613a4fb433e591aeef126",
                        "tags": [
                            "x_transferred"
                        ]
                    },
                    {
                        "url": "https://git.kernel.org/stable/c/38d20c62903d669693a1869aa68c4dd5674e2544",
                        "tags": [
                            "x_transferred"
                        ]
                    }
                ]
            },
            {
                "problemTypes": [
                    {
                        "descriptions": [
                            {
                                "type": "CWE",
                                "cweId": "CWE-416",
                                "lang": "en",
                                "description": "CWE-416 Use After Free"
                            }
                        ]
                    }
                ],
                "affected": [
                    {
                        "vendor": "linux",
                        "product": "linux_kernel",
                        "cpes": [
                            "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*"
                        ],
                        "defaultStatus": "affected",
                        "versions": [
                            {
                                "version": "5.15",
                                "status": "affected"
                            },
                            {
                                "version": "a848c4f15ab6",
                                "status": "affected",
                                "lessThan": "999daf367b92",
                                "versionType": "git"
                            },
                            {
                                "version": "a848c4f15ab6",
                                "status": "affected",
                                "lessThan": "380965e48e9c",
                                "versionType": "git"
                            },
                            {
                                "version": "a848c4f15ab6",
                                "status": "affected",
                                "lessThan": "24290ba94cd0",
                                "versionType": "git"
                            },
                            {
                                "version": "a848c4f15ab6",
                                "status": "affected",
                                "lessThan": "69d54650b751",
                                "versionType": "git"
                            },
                            {
                                "version": "a848c4f15ab6",
                                "status": "affected",
                                "lessThan": "38d20c62903d",
                                "versionType": "git"
                            }
                        ]
                    }
                ],
                "metrics": [
                    {
                        "cvssV3_1": {
                            "scope": "UNCHANGED",
                            "version": "3.1",
                            "baseScore": 7.8,
                            "attackVector": "LOCAL",
                            "baseSeverity": "HIGH",
                            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                            "integrityImpact": "HIGH",
                            "userInteraction": "NONE",
                            "attackComplexity": "LOW",
                            "availabilityImpact": "HIGH",
                            "privilegesRequired": "LOW",
                            "confidentialityImpact": "HIGH"
                        }
                    },
                    {
                        "other": {
                            "type": "ssvc",
                            "content": {
                                "timestamp": "2024-02-27T05:00:16.236632Z",
                                "id": "CVE-2024-26592",
                                "options": [
                                    {
                                        "Exploitation": "none"
                                    },
                                    {
                                        "Automatable": "no"
                                    },
                                    {
                                        "Technical Impact": "total"
                                    }
                                ],
                                "role": "CISA Coordinator",
                                "version": "2.0.3"
                            }
                        }
                    }
                ],
                "title": "CISA ADP Vulnrichment",
                "providerMetadata": {
                    "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
                    "shortName": "CISA-ADP",
                    "dateUpdated": "2024-08-27T15:00:34.971Z"
                }
            }
        ]
    }
}