2024-12-27 17:03:43 +00:00
{
"id" : "CVE-2024-56627" ,
"sourceIdentifier" : "416baaa9-dc9f-4396-8d5f-8c081fb06d67" ,
"published" : "2024-12-27T15:15:22.250" ,
2025-01-16 17:04:16 +00:00
"lastModified" : "2025-01-16T16:18:48.093" ,
"vulnStatus" : "Analyzed" ,
2024-12-27 17:03:43 +00:00
"cveTags" : [ ] ,
"descriptions" : [
{
"lang" : "en" ,
"value" : "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix Out-of-Bounds Read in ksmbd_vfs_stream_read\n\nAn offset from client could be a negative value, It could lead\nto an out-of-bounds read from the stream_buf.\nNote that this issue is coming when setting\n'vfs objects = streams_xattr parameter' in ksmbd.conf."
2025-01-05 03:03:46 +00:00
} ,
{
"lang" : "es" ,
"value" : "En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: ksmbd: se ha corregido la lectura fuera de los l\u00edmites en ksmbd_vfs_stream_read. Un desplazamiento del cliente podr\u00eda ser un valor negativo, lo que podr\u00eda provocar una lectura fuera de los l\u00edmites desde stream_buf. Tenga en cuenta que este problema se produce al configurar 'vfs objects = streams_xattr parameter' en ksmbd.conf."
2024-12-27 17:03:43 +00:00
}
] ,
2025-01-16 17:04:16 +00:00
"metrics" : {
"cvssMetricV31" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" ,
"baseScore" : 7.1 ,
"baseSeverity" : "HIGH" ,
"attackVector" : "LOCAL" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "LOW" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "HIGH" ,
"integrityImpact" : "NONE" ,
"availabilityImpact" : "HIGH"
} ,
"exploitabilityScore" : 1.8 ,
"impactScore" : 5.2
}
]
} ,
"weaknesses" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-125"
}
]
}
] ,
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*" ,
"versionStartIncluding" : "5.15" ,
"versionEndExcluding" : "5.15.176" ,
"matchCriteriaId" : "6877BC79-54F8-4872-9080-B8D0D2E4FC9C"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*" ,
"versionStartIncluding" : "5.16" ,
"versionEndExcluding" : "6.1.120" ,
"matchCriteriaId" : "09AC6122-E2A4-40FE-9D33-268A1B2EC265"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*" ,
"versionStartIncluding" : "6.2" ,
"versionEndExcluding" : "6.6.66" ,
"matchCriteriaId" : "29A976AD-B9AB-4A95-9F08-7669F8847EB9"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*" ,
"versionStartIncluding" : "6.7" ,
"versionEndExcluding" : "6.12.5" ,
"matchCriteriaId" : "9501D045-7A94-42CA-8B03-821BE94A65B7"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:linux:linux_kernel:6.13:rc1:*:*:*:*:*:*" ,
"matchCriteriaId" : "62567B3C-6CEE-46D0-BC2E-B3717FBF7D13"
}
]
}
]
}
] ,
2024-12-27 17:03:43 +00:00
"references" : [
{
"url" : "https://git.kernel.org/stable/c/27de4295522e9a33e4a3fc72f7b8193df9eebe41" ,
2025-01-16 17:04:16 +00:00
"source" : "416baaa9-dc9f-4396-8d5f-8c081fb06d67" ,
"tags" : [
"Patch"
]
2024-12-27 17:03:43 +00:00
} ,
2025-01-09 17:04:14 +00:00
{
"url" : "https://git.kernel.org/stable/c/6bd1bf0e8c42f10a9a9679a4c103a9032d30594d" ,
2025-01-16 17:04:16 +00:00
"source" : "416baaa9-dc9f-4396-8d5f-8c081fb06d67" ,
"tags" : [
"Patch"
]
2025-01-09 17:04:14 +00:00
} ,
2024-12-27 17:03:43 +00:00
{
"url" : "https://git.kernel.org/stable/c/81eed631935f2c52cdaf6691c6d48e0b06e8ad73" ,
2025-01-16 17:04:16 +00:00
"source" : "416baaa9-dc9f-4396-8d5f-8c081fb06d67" ,
"tags" : [
"Patch"
]
2024-12-27 17:03:43 +00:00
} ,
{
"url" : "https://git.kernel.org/stable/c/de4d790dcf53be41736239d7ee63849a16ff5d10" ,
2025-01-16 17:04:16 +00:00
"source" : "416baaa9-dc9f-4396-8d5f-8c081fb06d67" ,
"tags" : [
"Patch"
]
2024-12-27 17:03:43 +00:00
} ,
{
"url" : "https://git.kernel.org/stable/c/fc342cf86e2dc4d2edb0fc2ff5e28b6c7845adb9" ,
2025-01-16 17:04:16 +00:00
"source" : "416baaa9-dc9f-4396-8d5f-8c081fb06d67" ,
"tags" : [
"Patch"
]
2024-12-27 17:03:43 +00:00
}
]
}