Session race condition remote code execution vulnerability
CVE-2023-32258
8.1HIGH
What is CVE-2023-32258?
A vulnerability has been identified in the Linux kernel's ksmbd, which functions as a high-performance in-kernel SMB server. This flaw involves improper locking during the handling of SMB2_LOGOFF and SMB2_CLOSE commands. Due to this security lapse, an attacker could exploit the vulnerability to execute arbitrary code within the kernel context, potentially compromising system integrity and security.
Affected Version(s)
kernel 6.4-rc1
References
CVSS V3.1
Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved