Answer in brief
CVE-2024-35869 records a Unknown severity vulnerability in smb: client: guarantee refcounted children from parent session. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic), linux/linux_kernel (generic), linux/linux_kernel (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic), linux/linux_kernel (generic), linux/linux_kernel (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=8e3554150d6c80a84b3cb046615d1a0e943811dc <645f332c6b63499cc76197f9b6bffcc659ba64cc || >=8e3554150d6c80a84b3cb046615d1a0e943811dc <e1db9ae87b7148c021daee1fcc4bc71b2ac58a79 || >=8e3554150d6c80a84b3cb046615d1a0e943811dc <062a7f0ff46eb57aff526897bd2bebfdb1d3046a || f30d226bcc9f0e2d97b4a6e94c43a28148fbeab6 || c082c3be0f96e759ff2e361d929832fda0b93851 || >=6.2.15 <6.3 || >=6.3.2 <6.4 | 645f332c6b63499cc76197f9b6bffcc659ba64cc, e1db9ae87b7148c021daee1fcc4bc71b2ac58a79, 062a7f0ff46eb57aff526897bd2bebfdb1d3046a, 6.3, 6.4 |
| Linux/Linuxgeneric | 6.4 | Not reported |
| linux/linux_kernelgeneric | >=1da177e4c3f4 <645f332c6b63 | 645f332c6b63 |
| linux/linux_kernelgeneric | >=1da177e4c3f4 <e1db9ae87b71 | e1db9ae87b71 |
| linux/linux_kernelgeneric | >=1da177e4c3f4 <062a7f0ff46e | 062a7f0ff46e |
Published upstream
May 19, 2024
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: smb: client: guarantee refcounted children from parent session Avoid potential use-after-free bugs when walking DFS referrals, mounting and performing DFS failover by ensuring that all children from parent @tcon->ses are also refcounted. They're all needed across the entire DFS mount. Get rid of @tcon->dfs_ses_list while we're at it, too.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2024-35869 records a Unknown severity vulnerability in smb: client: guarantee refcounted children from parent session. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic), linux/linux_kernel (generic), linux/linux_kernel (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic), linux/linux_kernel (generic), linux/linux_kernel (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=8e3554150d6c80a84b3cb046615d1a0e943811dc <645f332c6b63499cc76197f9b6bffcc659ba64cc || >=8e3554150d6c80a84b3cb046615d1a0e943811dc <e1db9ae87b7148c021daee1fcc4bc71b2ac58a79 || >=8e3554150d6c80a84b3cb046615d1a0e943811dc <062a7f0ff46eb57aff526897bd2bebfdb1d3046a || f30d226bcc9f0e2d97b4a6e94c43a28148fbeab6 || c082c3be0f96e759ff2e361d929832fda0b93851 || >=6.2.15 <6.3 || >=6.3.2 <6.4 | 645f332c6b63499cc76197f9b6bffcc659ba64cc, e1db9ae87b7148c021daee1fcc4bc71b2ac58a79, 062a7f0ff46eb57aff526897bd2bebfdb1d3046a, 6.3, 6.4 |
| Linux/Linuxgeneric | 6.4 | Not reported |
| linux/linux_kernelgeneric | >=1da177e4c3f4 <645f332c6b63 | 645f332c6b63 |
| linux/linux_kernelgeneric | >=1da177e4c3f4 <e1db9ae87b71 | e1db9ae87b71 |
| linux/linux_kernelgeneric | >=1da177e4c3f4 <062a7f0ff46e | 062a7f0ff46e |
Published upstream
May 19, 2024
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: smb: client: guarantee refcounted children from parent session Avoid potential use-after-free bugs when walking DFS referrals, mounting and performing DFS failover by ensuring that all children from parent @tcon->ses are also refcounted. They're all needed across the entire DFS mount. Get rid of @tcon->dfs_ses_list while we're at it, too.
Quoted source text, attributed separately from HOL analysis.