smb: client: protect tc_count increment in smb2_find_smb_sess_tcon_unlocked()
28Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 9.8epss 0.5%
exploitation probability
0.5%top 60% of all CVEs
observed exploitation
nono source reports it
In the Linux kernel, the following vulnerability has been resolved:
smb: client: protect tc_count increment in smb2_find_smb_sess_tcon_unlocked()
Commit 96c4af418586 ("cifs: Fix locking usage for tcon fields")
refactored cifs code to change cifs_tcp_ses_lock for tc_lock around
tc_count changes.
There was missing lock around tc_count increment inside
smb2_find_smb_sess_tcon_unlocked().
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
Linux · LinuxReferences
https://git.kernel.org/stable/c/13fb413ae22a37c69341918a6d651d19a9b0b9b7https://git.kernel.org/stable/c/4d8690dace005a38e6dbde9ecce2da3ad85c7c41https://git.kernel.org/stable/c/7df1df6f40c0720d30206aa35c0343b962350e0dhttps://git.kernel.org/stable/c/bf4ebdb19ff9b3cdf992b50715fe61633327416ahttps://git.kernel.org/stable/c/e374f4e496fef8168784f93a4477d67be34485fd