发布于3月6日3月6日 Members Red Hat: CVE-2024-35869: kernel: smb: client: guarantee refcounted children from parent session (Multiple Advisories) Severity 5 CVSS (AV:L/AC:L/Au:S/C:N/I:N/A:C) Published 05/19/2024 Created 12/06/2024 Added 12/05/2024 Modified 12/05/2024 Description In the Linux kernel, the following vulnerability has been resolved: smb: client: guarantee refcounted children from parent session Avoid potential use-after-free bugs when walking DFS referrals, mounting and performing DFS failover by ensuring that all children from parent @tcon->ses are also refcounted.They're all needed across the entire DFS mount.Get rid of @tcon->dfs_ses_list while we're at it, too. Solution(s) redhat-upgrade-kernel redhat-upgrade-kernel-rt References CVE-2024-35869 RHSA-2024:9315