CVE-2023-32254
Summary
| CVE | CVE-2023-32254 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-07-10 16:15:00 UTC |
| Updated | 2023-11-07 04:14:00 UTC |
| Description | A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within the processing of SMB2_TREE_DISCONNECT commands. The issue results from the lack of proper locking when performing operations on an object. An attacker can leverage this vulnerability to execute code in the context of the kernel. |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|
| Operating System |
Linux |
Linux Kernel |
All |
All |
All |
All |
References
| Reference | Source | Link | Tags |
|---|
| ZDI-23-702 | Zero Day Initiative |
MISC |
www.zerodayinitiative.com |
|
| cve-details |
MISC |
access.redhat.com |
|
| 2191658 – (CVE-2023-32254, ZDI-23-702, ZDI-CAN-20592) CVE-2023-32254 kernel: ksmbd: tree connection race condition remote code execution vulnerability |
MISC |
bugzilla.redhat.com |
|
| July 2023 Linux Kernel 6.4 Vulnerabilities in NetApp Products | NetApp Product Security |
MISC |
security.netapp.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 199421 Ubuntu Security Notification for Linux kernel (OEM) Vulnerabilities (USN-6173-1)
- 199652 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6283-1)
- 200243 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6725-1)
- 6000207 Debian Security Update for linux (DSA 5448-1)
- 907083 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (27402-1)
- 907124 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (27400-1)
- 907860 Common Base Linux Mariner (CBL-Mariner) Security Update for hyperv-daemons (27634-1)