smb2_allocate_rsp_buf of the component ksmbd. The manipulation results in out-of-bounds read.
This vulnerability is known as CVE-2024-26980. Access to the local network is required for this attack. No exploit is available.
It is suggested to upgrade the affected component.
Intelligence View
⚡ tsecurity.de Intelligence
CVE-2024-26980 | Linux Kernel up to 6.1.87/6.6.28/6.8.7/6.9-rc5 ksmbd smb2_allocate_rsp_buf out-of-bounds (Nessus ID 227886 / WID-SEC-2024-1008)
A vulnerability was found in Linux Kernel up to 6.1.87/6.6.28/6.8.7/6.9-rc5 and classified as problematic. Affected by this issue is the function
SOCIAL SHARE CARD GENERATOR