Overview
About vulnerability
In the Linux kernel, the following vulnerability has been resolved:
smb: client: clear ce->tgthint in free_tgts()
When free_tgts() frees all structures in ce->tlist, ce->tgthint is left pointing to one of the freed cache_dfs_tgt structures.
If ce->tgthint is not reset before it is used later, it results in a use-after-free.
Set ce->tgthint to NULL in free_tgts() after the elements are freed to reflect that no elements remain.
Details
- Affected product:
- Debian 10 ELS , Debian 11 ELS , Ubuntu 20.04 ELS
- Affected packages:
- linux @ 4.19.0 (+2 more)