Summary
In the Linux kernel, specifically in the smb client, a use-after-free (UAF) vulnerability in the cifs_debug_files_proc_show() function was discovered. This occurs when sessions that are being torn down (status == SES_EXITING) are not properly skipped, leading to potential memory corruption
Products Potentially Affected
OS/Product
|
Exposure
|
ExtremeAnalytics for Site Engine
|
Yes
|
ExtremeCloud IQ - Site Engine (XIQ-SE)
|
Yes
|
ExtremeControl for Site Engine
|
Yes
|
Repair Recommendations
ExtremeAnalytics for Site Engine:
- Fixed in 25.5.10.61 or later.
ExtremeCloud IQ - Site Engine (XIQ-SE):
- Fixed in 25.5.10.61 or later.
ExtremeControl for Site Engine:
- Fixed in 25.5.10.61 or later
Please see the full security advisory article here for more details and future updates.