Junglewise Threat Intelligence

CVE-2024-50151: Linux Kernel SMB client out-of-bounds write in SMB2_IOCTL request

CVE-2024-50151 · Severity: high · CVSS 7.8 · Published 2024-11-07

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's SMB (file sharing) client could allow a local user to crash the system or potentially execute unauthorized code. The issue occurs when the system handles encrypted file sharing requests, specifically when creating certain types of file links. This could lead to a loss of system availability or unauthorized access to sensitive kernel memory.

Technical details

The vulnerability is a heap-based out-of-bounds (OOB) write (CWE-787) within the 'cifs' module of the Linux kernel. When encryption is enforced (via the 'seal' mount option or server policy), the client squashes compound request buffers into a single iov in 'smb2_set_next_command()'. 'SMB2_ioctl_init()' allocates a small 448-byte buffer, but if a user provides an input buffer exceeding 328 bytes (e.g., via a long symlink target), the subsequent write exceeds the allocated 'iov_base' boundary. This was demonstrated using a 1024-byte symlink path which resulted in a 4116-byte OOB write. Patches have been released for various stable kernel branches including 5.4.y, 5.10.y, 5.15.y, 6.1.y, 6.6.y, and 6.11.y.

Affected products

  • Linux Linux Kernel 5.0 to 5.4.285, 5.5 to 5.10.229, 5.11 to 5.15.170, 5.16 to 6.1.115, 6.2 to 6.6.59, 6.7 to 6.11.6, 6.12-rc1 to 6.12-rc3

Timeline

  • 2024-10-15: patched: Initial fix authored by Paulo Alcantara
  • 2024-11-07: disclosed: CVE-2024-50151 published

References

Related threats