Back to Database
Status published
Unknown
CVE-2024-35866
smb: client: fix potential UAF in cifs_dump_full_key()
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential UAF in cifs_dump_full_key() Skip sessions that are being teared down (status == SES_EXITING) to avoid UAF.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-35866
Credits & Attribution
No credits recorded in the NVD database.
References
- https://git.kernel.org/stable/c/d798fd98e3563027c5162259ead517057d6fa794
- https://git.kernel.org/stable/c/f4a60d360d9114b5085701a3702a0102b0d6d846
- https://git.kernel.org/stable/c/10e17ca4000ec34737bde002a13435c38ace2682
- https://git.kernel.org/stable/c/3103163ccd3be4adcfa37e15608fb497be044113
- https://git.kernel.org/stable/c/58acd1f497162e7d282077f816faa519487be045
More from Linux
View All →CVE-2025-71315
drm/vkms: Convert to DRM's vblank timer
Unknown
0
CVE-2025-71314
drm/panthor: Recover from panthor_gpu_flush_caches() failures
Unknown
0
CVE-2025-71313
PCI: endpoint: Add missing NULL check for alloc_workqueue()
Unknown
0
CVE-2025-71312
fs/ntfs3: fix ntfs_mount_options leak in ntfs_fill_super()
Unknown
0
CVE-2025-71311
fs/ntfs3: Initialize new folios before use
Unknown
0
Affected Vendor
Linux
View all reports →Affected Software
Linux
Vulnerable Versions:
1bb56810677f26b78d57a3038054943efd334a1c, 5.13, 0, 5.15.181, 6.1.132, 6.6.26, 6.8.5, 6.9
Timeline
Official Publish:
May 19th, 2024
Last Modified:
May 11th, 2026
Added to House:
July 22nd, 2026
CVSS Vectors
No vector data available
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.