CVE-2024-26954 | Linux Kernel up to 6.7.11/6.8.2 ksmbd smb_strndup_from_utf16 out-of-bounds (3b8da67191e9/4f97e6a9d62c/a80a486d72e2 / Nessus ID 211777)
A vulnerability marked as problematic has been reported in Linux Kernel up to 6.7.11/6.8.2. This impacts the function smb_strndup_from_utf16 of the component ksmbd. Performing manipulation results in out-of-bounds read.
This vulnerability was named CVE-2024-26954. The attack needs to be approached within the local network. There is no available exploit.
It is suggested to upgrade the affected component.