CVE-2023-32247
Summary
| CVE | CVE-2023-32247 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-07-24 16:15:00 UTC |
| Updated | 2023-12-04 14:55:00 UTC |
| Description | A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within the handling of SMB2_SESSION_SETUP commands. The issue results from the lack of control of resource consumption. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| cve-details |
MISC |
access.redhat.com |
|
| July 2023 Linux Kernel 6.3.9 Vulnerabilities in NetApp Products | NetApp Product Security |
MISC |
security.netapp.com |
|
| 2219803 – (CVE-2023-32247, ZDI-23-695, ZDI-CAN-20478) CVE-2023-32247 kernel: ksmbd: session setup memory exhaustion denial-of-service vulnerability |
MISC |
bugzilla.redhat.com |
|
| ZDI-23-695 | Zero Day Initiative |
MISC |
www.zerodayinitiative.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 200210 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6704-1)
- 200214 Ubuntu Security Notification for Linux kernel (AWS) Vulnerabilities (USN-6705-1)
- 200218 Ubuntu Security Notification for Linux kernel (Raspberry Pi) Vulnerabilities (USN-6704-2)
- 200223 Ubuntu Security Notification for Linux kernel (Oracle) Vulnerabilities (USN-6704-3)
- 200237 Ubuntu Security Notification for Linux kernel (Intel IoTG) Vulnerabilities (USN-6704-4)
- 907844 Common Base Linux Mariner (CBL-Mariner) Security Update for hyperv-daemons (27643-1)