CVE-2024-49988: Linux Kernel
Medium severity, CVSS 5.5. EPSS: 0.6% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: ksmbd: add refcnt to ksmbd_conn struct When sending an oplock break request, opinfo->conn is used, But freed ->conn can be used on multichannel. This patch add a reference count to the ksmbd_conn struct so that it can be freed when it is no longer used.
Affected products
- Linux Linux Kernel: before 6.6.55 (fixed in 6.6.55); from 6.7, before 6.10.14 (fixed in 6.10.14); from 6.11, before 6.11.3 (fixed in 6.11.3)
Published 2024-10-21. Last modified 2026-08-04.