{"id":"CVE-2024-0565","title":"An out-of-bounds memory read flaw was found in receive_encrypted_standard in fs/smb/client/smb2ops.c in the SMB Client sub-component in the Linux Kernel","summary":"An out-of-bounds memory read flaw was found in receive_encrypted_standard in fs/smb/client/smb2ops.c in the SMB Client sub-component in the Linux Kernel. This issue occurs due to integer underflow on the memcpy length, leading to a denia…","severity":"medium","cvss":6.8,"cvssVector":"CVSS:3.1/AV:A/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H","cwe":["CWE-191","CWE-191"],"vendor":"netapp","product":"ontap_tools","affected":["linux_kernel >= 6.1.36, < 6.7","linux_kernel = 6.7","ontap_tools"],"patched":["linux_kernel 6.7"],"published":"2024-01-15","updated":"2026-08-10","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2024-0565","references":[{"url":"https://access.redhat.com/errata/RHSA-2024:1188","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2024:1404","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2024:1532","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2024:1533","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2024:1607","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2024:1614","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2024:2093","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2024:2394","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/security/cve/CVE-2024-0565","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2258518","label":"secalert@redhat.com"},{"url":"https://www.spinics.net/lists/stable-commits/msg328851.html","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2024:1188","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2024:1404","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2024:1532","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2024:1533","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2024:1607","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2024:1614","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2024:2093","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2024:2394","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/security/cve/CVE-2024-0565","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2258518","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2024/06/msg00017.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.netapp.com/advisory/ntap-20240223-0002/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.spinics.net/lists/stable-commits/msg328851.html","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.01999,"epssPercentile":0.79606,"ingestedAt":"2026-08-11T16:47:02.553Z","slug":"CVE-2024-0565","body":"## Overview\n\nAn out-of-bounds memory read flaw was found in receive_encrypted_standard in fs/smb/client/smb2ops.c in the SMB Client sub-component in the Linux Kernel. This issue occurs due to integer underflow on the memcpy length, leading to a denial of service.\n\n## Affected\n\n- `linux_kernel >= 6.1.36, < 6.7`\n- `linux_kernel = 6.7`\n- `ontap_tools`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `linux_kernel 6.7`","depth":"sunlit","depthScore":38,"depthScoreParts":{"impact":37.4,"likelihood":0.4,"exploitation":0,"ransomware":0},"changes":[]}