CVE-2023-32248
Summary
| CVE | CVE-2023-32248 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-07-24 16:15:00 UTC |
| Updated | 2023-12-04 14:54:00 UTC |
| Description | A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within the handling of SMB2_TREE_CONNECT and SMB2_QUERY_INFO commands. The issue results from the lack of proper validation of a pointer prior to accessing it. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| ZDI-23-696 | Zero Day Initiative |
MISC |
www.zerodayinitiative.com |
|
| 2219818 – (CVE-2023-32248, ZDI-23-696, ZDI-CAN-20479) CVE-2023-32248 kernel: ksmbd: tree connection NULL pointer dereference denial-of-service vulnerability |
MISC |
bugzilla.redhat.com |
|
| cve-details |
MISC |
access.redhat.com |
|
| CVE-2023-32248 Linux Kernel Vulnerability in NetApp Products | NetApp Product Security |
MISC |
security.netapp.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 199652 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6283-1)
- 199670 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6300-1)