NVD disclosure day

Published threat advisories for May 19, 2024

CVE advisoryCRITICAL

CVE-2024-35870

Linux Kernel UAF in SMB Client Reconnect Feature.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A use-after-free vulnerability exists in the Linux kernel's SMB client when reconnecting to a server, potentially causing system instability or compromise. This issue impacts the client-side component used for connecting to network file shares. The primary concern is to determine if this component is in use within the

CVE advisoryCRITICAL

CVE-2024-35869

Linux Kernel SMB Use-After-Free Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the Linux kernel's SMB client could allow for memory corruption when handling DFS referrals. This might lead to system instability or unpredictable behavior when accessing network resources. While the specific conditions to exploit this are complex, systems utilizing SMB with DFS referrals are potent

CVE advisoryCRITICAL

CVE-2024-35865

Linux Kernel SMB Client Use-After-Free Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A use-after-free vulnerability in the Linux kernel's SMB client could permit unauthorized data access or modification. Exploitation requires network access and specifically targets the SMB client functionality, though the likelihood of impact is considered unlikely for most organizations.