{"api_version":"1","generated_at":"2026-07-23T14:39:51+00:00","cve":"CVE-2024-58087","urls":{"html":"https://cve.report/CVE-2024-58087","api":"https://cve.report/api/cve/CVE-2024-58087.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2024-58087","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2024-58087"},"summary":{"title":"ksmbd: fix racy issue from session lookup and expire","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix racy issue from session lookup and expire\n\nIncrement the session reference count within the lock for lookup to avoid\nracy issue with session expire.","state":"PUBLISHED","assigner":"Linux","published_at":"2025-03-12 08:15:11","updated_at":"2026-04-23 13:48:41"},"problem_types":["CWE-667","CWE-667 CWE-667 Improper Locking"],"metrics":[{"version":"3.1","source":"nvd@nist.gov","type":"Primary","score":"8.1","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"ADP","type":"DECLARED","score":"8.1","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","data":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":8.1,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}},{"version":"3.1","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","score":"8.1","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}}],"references":[{"url":"https://git.kernel.org/stable/c/b95629435b84b9ecc0c765995204a4d8a913ed52","name":"https://git.kernel.org/stable/c/b95629435b84b9ecc0c765995204a4d8a913ed52","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":["Patch"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/a39e31e22a535d47b14656a7d6a893c7f6cf758c","name":"https://git.kernel.org/stable/c/a39e31e22a535d47b14656a7d6a893c7f6cf758c","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":["Patch"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/450a844c045ff0895d41b05a1cbe8febd1acfcfd","name":"https://git.kernel.org/stable/c/450a844c045ff0895d41b05a1cbe8febd1acfcfd","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":["Patch"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/2107ab40629aeabbec369cf34b8cf0f288c3eb1b","name":"https://git.kernel.org/stable/c/2107ab40629aeabbec369cf34b8cf0f288c3eb1b","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":["Patch"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.zerodayinitiative.com/advisories/ZDI-25-100/","name":"https://www.zerodayinitiative.com/advisories/ZDI-25-100/","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":["Patch","Third Party Advisory"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/37a0e2b362b3150317fb6e2139de67b1e29ae5ff","name":"https://git.kernel.org/stable/c/37a0e2b362b3150317fb6e2139de67b1e29ae5ff","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":["Patch"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2024-58087","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2024-58087","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 0626e6641f6b467447c81dd7678a69c66f7746cf 2107ab40629aeabbec369cf34b8cf0f288c3eb1b git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 0626e6641f6b467447c81dd7678a69c66f7746cf 37a0e2b362b3150317fb6e2139de67b1e29ae5ff git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 0626e6641f6b467447c81dd7678a69c66f7746cf 450a844c045ff0895d41b05a1cbe8febd1acfcfd git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 0626e6641f6b467447c81dd7678a69c66f7746cf a39e31e22a535d47b14656a7d6a893c7f6cf758c git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 0626e6641f6b467447c81dd7678a69c66f7746cf b95629435b84b9ecc0c765995204a4d8a913ed52 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 5.15","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.15 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.15.176 5.15.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.1.121 6.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.6.67 6.6.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.12.6 6.12.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.13 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2024","cve_id":"58087","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"linux","cpe5":"linux_kernel","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"cvssV3_1":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":8.1,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}},{"other":{"content":{"id":"CVE-2024-58087","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","timestamp":"2025-10-01T19:26:55.319254Z","version":"2.0.3"},"type":"ssvc"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-667","description":"CWE-667 Improper Locking","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2025-10-01T19:36:35.134Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["fs/smb/server/auth.c","fs/smb/server/mgmt/user_session.c","fs/smb/server/server.c","fs/smb/server/smb2pdu.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"2107ab40629aeabbec369cf34b8cf0f288c3eb1b","status":"affected","version":"0626e6641f6b467447c81dd7678a69c66f7746cf","versionType":"git"},{"lessThan":"37a0e2b362b3150317fb6e2139de67b1e29ae5ff","status":"affected","version":"0626e6641f6b467447c81dd7678a69c66f7746cf","versionType":"git"},{"lessThan":"450a844c045ff0895d41b05a1cbe8febd1acfcfd","status":"affected","version":"0626e6641f6b467447c81dd7678a69c66f7746cf","versionType":"git"},{"lessThan":"a39e31e22a535d47b14656a7d6a893c7f6cf758c","status":"affected","version":"0626e6641f6b467447c81dd7678a69c66f7746cf","versionType":"git"},{"lessThan":"b95629435b84b9ecc0c765995204a4d8a913ed52","status":"affected","version":"0626e6641f6b467447c81dd7678a69c66f7746cf","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["fs/smb/server/auth.c","fs/smb/server/mgmt/user_session.c","fs/smb/server/server.c","fs/smb/server/smb2pdu.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"5.15"},{"lessThan":"5.15","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"5.15.*","status":"unaffected","version":"5.15.176","versionType":"semver"},{"lessThanOrEqual":"6.1.*","status":"unaffected","version":"6.1.121","versionType":"semver"},{"lessThanOrEqual":"6.6.*","status":"unaffected","version":"6.6.67","versionType":"semver"},{"lessThanOrEqual":"6.12.*","status":"unaffected","version":"6.12.6","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"6.13","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"5.15.176","versionStartIncluding":"5.15","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.1.121","versionStartIncluding":"5.15","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.6.67","versionStartIncluding":"5.15","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.12.6","versionStartIncluding":"5.15","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.13","versionStartIncluding":"5.15","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix racy issue from session lookup and expire\n\nIncrement the session reference count within the lock for lookup to avoid\nracy issue with session expire."}],"providerMetadata":{"dateUpdated":"2025-05-04T10:09:47.171Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/2107ab40629aeabbec369cf34b8cf0f288c3eb1b"},{"url":"https://git.kernel.org/stable/c/37a0e2b362b3150317fb6e2139de67b1e29ae5ff"},{"url":"https://git.kernel.org/stable/c/450a844c045ff0895d41b05a1cbe8febd1acfcfd"},{"url":"https://git.kernel.org/stable/c/a39e31e22a535d47b14656a7d6a893c7f6cf758c"},{"url":"https://git.kernel.org/stable/c/b95629435b84b9ecc0c765995204a4d8a913ed52"},{"url":"https://www.zerodayinitiative.com/advisories/ZDI-25-100/"}],"title":"ksmbd: fix racy issue from session lookup and expire","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2024-58087","datePublished":"2025-03-12T07:28:09.114Z","dateReserved":"2025-03-06T15:52:09.185Z","dateUpdated":"2025-10-01T19:36:35.134Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2025-03-12 08:15:11","lastModifiedDate":"2026-04-23 13:48:41","problem_types":["CWE-667","CWE-667 CWE-667 Improper Locking"],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.2,"impactScore":5.9},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.2,"impactScore":5.9}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.15.145","versionEndExcluding":"5.15.176","matchCriteriaId":"5258FF49-104E-4A25-8BF2-5FAC8A3CB92B"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.1.29","versionEndExcluding":"6.1.121","matchCriteriaId":"63AC31AB-1504-438D-ADB2-992A6B2314E9"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.2.16","versionEndExcluding":"6.3","matchCriteriaId":"16E4CFA4-3F36-4CF1-9C4C-B185D57ECE60"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.3.2","versionEndExcluding":"6.4","matchCriteriaId":"D34CEEAF-3FD7-4A5F-98C7-05AA7558CEF6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.7","versionEndExcluding":"6.12.6","matchCriteriaId":"0CB1A9BB-F95E-43DD-A2FD-147912FD91E5"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:6.13:rc1:*:*:*:*:*:*","matchCriteriaId":"62567B3C-6CEE-46D0-BC2E-B3717FBF7D13"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:6.13:rc2:*:*:*:*:*:*","matchCriteriaId":"5A073481-106D-4B15-B4C7-FB0213B8E1D4"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2024","CveId":"58087","Ordinal":"1","Title":"ksmbd: fix racy issue from session lookup and expire","CVE":"CVE-2024-58087","Year":"2024"},"notes":[{"CveYear":"2024","CveId":"58087","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix racy issue from session lookup and expire\n\nIncrement the session reference count within the lock for lookup to avoid\nracy issue with session expire.","Type":"Description","Title":"ksmbd: fix racy issue from session lookup and expire"}]}}}