SB2024070721 - Resource management error in Linux kernel cifs
Published: July 7, 2024 Updated: May 13, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Resource management error (CVE-ID: CVE-2021-46960)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to resource management error within the smb2_get_enc_key() function in fs/cifs/smb2ops.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/e94851629c49c65b4fbb29a5725ddfd7988f8f20
- https://git.kernel.org/stable/c/e486f8397f3f14a7cadc166138141fdb14379a54
- https://git.kernel.org/stable/c/93f3339b22ba17e66f0808737467b70ba087eaec
- https://git.kernel.org/stable/c/aaa0faa5c28a91c362352d6b35dc3ed10df56fb0
- https://git.kernel.org/stable/c/f59a9242942fef0de7b926e438ba4eae65d4b4dd
- https://git.kernel.org/stable/c/b399c1a3ea0b9d10047ff266d65533df7f15532f
- https://git.kernel.org/stable/c/83728cbf366e334301091d5b808add468ab46b27
- https://mirrors.edge.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.233
- https://mirrors.edge.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.191
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.36
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.11.20
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.12.3
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.13
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.4.118