OOB Read in SMB Client due to Integer Underflow CVE-2024-0565
CVE-2024-0565 Published on January 15, 2024
Kernel: cifs filesystem decryption improper input validation remote code execution vulnerability in function receive_encrypted_standard of client
An out-of-bounds memory read flaw was found in receive_encrypted_standard in fs/smb/client/smb2ops.c in the SMB Client sub-component in the Linux Kernel. This issue occurs due to integer underflow on the memcpy length, leading to a denial of service.
Vulnerability Analysis
Timeline
Reported to Red Hat.
Made public.
Weakness Type
What is an Integer underflow Vulnerability?
The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result. This can happen in signed and unsigned cases.
CVE-2024-0565 has been classified to as an Integer underflow vulnerability or weakness.
Products Associated with CVE-2024-0565
You can be notified by email with stack.watch whenever vulnerabilities like CVE-2024-0565 are published in these products:
Affected Versions
Linux kernel:- Version 4.19 and below 5.10.211 is affected.
- Version 5.11 and below 5.15.150 is affected.
- Version 5.16 and below 6.1.69 is affected.
- Version 6.2 and below 6.6.8 is affected.
- Version 0:4.18.0-513.24.1.rt7.326.el8_9 and below * is unaffected.
- Version 0:4.18.0-513.24.1.el8_9 and below * is unaffected.
- Version 0:4.18.0-372.95.1.el8_6 and below * is unaffected.
- Version 0:4.18.0-477.51.1.el8_8 and below * is unaffected.
- Version 0:5.14.0-427.13.1.el9_4 and below * is unaffected.
- Version 0:5.14.0-427.13.1.el9_4 and below * is unaffected.
- Version 0:5.14.0-284.59.1.el9_2 and below * is unaffected.
- Version 0:5.14.0-284.59.1.rt14.344.el9_2 and below * is unaffected.
- Version 0:4.18.0-372.95.1.el8_6 and below * is unaffected.
- Version v5.7.13-16 and below * is unaffected.
- Version v5.7.13-7 and below * is unaffected.
- Version v6.8.1-408 and below * is unaffected.
- Version v5.7.13-19 and below * is unaffected.
- Version v1.0.0-480 and below * is unaffected.
- Version v5.7.13-9 and below * is unaffected.
- Version v0.4.0-248 and below * is unaffected.
- Version v1.14.6-215 and below * is unaffected.
- Version v6.8.1-431 and below * is unaffected.
- Version v1.1.0-228 and below * is unaffected.
- Version v5.8.1-471 and below * is unaffected.
- Version v2.9.6-15 and below * is unaffected.
- Version v5.7.13-3 and below * is unaffected.
- Version v5.7.13-27 and below * is unaffected.
- Version v5.7.13-12 and below * is unaffected.
- Version v0.1.0-527 and below * is unaffected.
- Version v0.1.0-225 and below * is unaffected.
- Version v0.28.1-57 and below * is unaffected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.