LiveActive security incident?Get immediate response
CVE Record

CVE-2024-26928: smb: client: fix potential UAF in cifs_debug_files_proc_show()

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential UAF in cifs_debug_files_proc_show() Skip sessions that are being teared down (status == SES_EXITING) to avoid UAF.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysisunknown

Security readout for executives and security teams

Plain-English summary

CVE-2024-26928 is a Linux kernel SMB client memory-safety flaw. The kernel fix avoids a possible use-after-free when showing CIFS debug file information while an SMB session is being torn down. Business urgency depends on Linux kernel exposure, not an application deployment alone.

Executive priority

Handle through normal kernel patch governance unless local exposure is broad or SMB/CIFS use is business-critical. There is no source-backed evidence of active exploitation, but kernel memory-safety flaws deserve timely remediation because impact details are incomplete.

Technical view

The resolved kernel change skips SMB client sessions with status SES_EXITING in cifs_debug_files_proc_show() to avoid a potential use-after-free. The source bundle lists affected Linux kernel version ranges and multiple stable kernel fix commits, but provides no CVSS, CWE, or detailed impact statement.

Likely exposure

Potentially exposed systems are Linux hosts running affected kernel versions with SMB/CIFS client code in use. The supplied sources do not prove exposure for every Linux deployment, and they do not describe a complete attack path or required privileges.

Exploitation context

The CVE is not marked as CISA KEV in the bundle. No cited source states active exploitation, public exploit availability, or remote weaponization. Treat this as a kernel memory-safety issue requiring patch tracking, with exploitability details incomplete.

Researcher notes

Focus validation on whether cifs_debug_files_proc_show() can observe a session during teardown on affected kernels. The bundle does not include crash details, privilege requirements, or exploitability analysis, so avoid assuming remote code execution or active abuse.

Mitigation direction

  • Apply vendor kernel updates containing the referenced stable fixes.
  • For Debian LTS systems, review the linked Debian LTS advisory.
  • Track Linux distribution advisories for backported fixed kernel packages.
  • Prioritize updating systems that mount or use SMB/CIFS shares.
  • If updates are delayed, review vendor guidance for safe temporary mitigations.

Validation and detection

  • Inventory running Linux kernel versions against the CVE affected ranges.
  • Confirm installed kernel packages include the relevant stable fix or vendor backport.
  • Identify hosts using SMB/CIFS client functionality or mounts.
  • Check vulnerability scanners for distribution-specific fixed package detection.
  • Document exceptions where kernel updates cannot be applied immediately.
Prepared
Confidence
medium
Sources
9

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2024-26928 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
3Timeline events
2ADP providers
8Source links

SSVC decision data

CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: noneAutomatable: noTechnical Impact: partial

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. CVE publishedCVE Program

    The CVE record was published.

  3. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

ADP provider summaries

CISA-ADPCISA ADP Vulnrichment
other:ssvc
CVECVE Program Container
Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
LinuxLinuxdfe33f9abc08997e56f9bdf14fe9ac7ac0e14075, dfe33f9abc08997e56f9bdf14fe9ac7ac0e14075, dfe33f9abc08997e56f9bdf14fe9ac7ac0e14075, dfe33f9abc08997e56f9bdf14fe9ac7ac0e14075, dfe33f9abc08997e56f9bdf14fe9ac7ac0e14075, dfe33f9abc08997e56f9bdf14fe9ac7ac0e14075unaffected
LinuxLinux4.20, 0, 5.10.237, 5.15.180, 6.1.85, 6.6.26, 6.8.5, 6.9affected
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.