High severity7.8NVD Advisory· Published May 19, 2024· Updated Apr 21, 2026
CVE-2024-35866
CVE-2024-35866
Description
In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix potential UAF in cifs_dump_full_key()
Skip sessions that are being teared down (status == SES_EXITING) to avoid UAF.
Affected products
4- cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
Patches
5d798fd98e356f4a60d360d9110e17ca4000e3103163ccd3b58acd1f49716Vulnerability mechanics
Generated by null/stub on May 9, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.
References
1- lists.debian.org/debian-lts-announce/2025/05/msg00045.htmlnvdMailing ListThird Party Advisory
News mentions
0No linked articles in our index yet.