CVE-2024-57925: Linux Kernel
High severity, CVSS 7.1. EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix a missing return value check bug In the smb2_send_interim_resp(), if ksmbd_alloc_work_struct() fails to allocate a node, it returns a NULL pointer to the in_work pointer. This can lead to an illegal memory write of in_work->response_buf when allocate_interim_rsp_buf() attempts to perform a kzalloc() on it. To address this issue, incorporating a check for the return value of ksmbd_alloc_work_struct() ensures that the function returns immediately upon allocation failure, thereby preventing the aforementioned illegal memory access.
Affected products
- Linux Linux Kernel: from 5.15.145, before 5.16 (fixed in 5.16); from 6.1.71, before 6.1.125 (fixed in 6.1.125); from 6.6, before 6.6.72 (fixed in 6.6.72); from 6.7, before 6.12.10 (fixed in 6.12.10); version 6.13 only
Published 2025-01-19. Last modified 2026-06-17.