Tree connection null pointer dereference denial-of-service vulnerability
CVE-2023-32248
7.5HIGH
What is CVE-2023-32248?
A vulnerability in the Linux kernel's ksmbd, a high-performance in-kernel SMB server, was identified due to improper validation of pointers when handling SMB2_TREE_CONNECT and SMB2_QUERY_INFO commands. This flaw could be exploited by an attacker to cause a denial-of-service condition, impacting system availability. Users and administrators are advised to verify their systems against this vulnerability and apply necessary patches from their distribution providers.
Affected Version(s)
kernel 6.4-rc1
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved