CVE-2023-32258
Summary
| CVE | CVE-2023-32258 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-07-24 16:15:00 UTC |
| Updated | 2023-11-17 18:29:00 UTC |
| Description | A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within the processing of SMB2_LOGOFF and SMB2_CLOSE commands. The issue results from the lack of proper locking when performing operations on an object. An attacker can leverage this vulnerability to execute code in the context of the kernel. |
Risk And Classification
Problem Types: CWE-667
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| cve-details | MISC | access.redhat.com | |
| ZDI-23-706 | Zero Day Initiative | MISC | www.zerodayinitiative.com | |
| July 2023 Linux Kernel 6.3.9 Vulnerabilities in NetApp Products | NetApp Product Security | MISC | security.netapp.com | |
| 2219809 – (CVE-2023-32258, ZDI-23-706, ZDI-CAN-20796) CVE-2023-32258 kernel: ksmbd: session race condition remote code execution vulnerability | MISC | bugzilla.redhat.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.