Tree connection null pointer dereference denial-of-service vulnerability
CVE-2023-32248

7.5HIGH

What is CVE-2023-32248?

A vulnerability in the Linux kernel's ksmbd, a high-performance in-kernel SMB server, was identified due to improper validation of pointers when handling SMB2_TREE_CONNECT and SMB2_QUERY_INFO commands. This flaw could be exploited by an attacker to cause a denial-of-service condition, impacting system availability. Users and administrators are advised to verify their systems against this vulnerability and apply necessary patches from their distribution providers.

Affected Version(s)

kernel 6.4-rc1

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.