PT-2023-2824 · Linux+5 · Linux Kernel+5

Quentin Minster

+1

·

Published

2023-04-27

·

Updated

2024-08-27

·

CVE-2023-32247

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux Kernel (affected versions not specified)
Description A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The issue results from the lack of control of resource consumption when handling SMB2 SESSION SETUP commands. An attacker can leverage this to create a denial-of-service condition on the system. The vulnerability is related to incorrect resource release, allowing a remote attacker to cause a denial-of-service using the SMB2 SESSION SETUP command.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Improper Resource Release

Memory Leak

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2024-4263
ALT-PU-2024-4843
AZL-27643
AZL-27765
BDU:2023-02750
CVE-2023-32247
OESA-2023-1634
OESA-2023-1635
OESA-2023-1636
USN-6338-1
USN-6338-2
USN-6344-1
USN-6704-1
USN-6704-2
USN-6704-3
USN-6704-4
USN-6705-1
ZDI-23-695

Affected Products

Alt Linux
Astra Linux
Linux Kernel
Linuxmint
Red Os
Ubuntu