← Back

CVE-2023-32248

nvd nist
Published: Jul 24, 2023Modified: Jun 17, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within the handling of SMB2_TREE_CONNECT and SMB2_QUERY_INFO commands. The issue results from the lack of proper validation of a pointer prior to accessing it. An attacker can leverage this vulnerability to create a denial-of-service condition on the system.

Affected (9)

1 product
Linux Kernel
5 products
H300s
H410c
H410s
H500s
H700s
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Linux
From 5.15 to 5.15.111
From 5.16 to 6.1.28
From 6.2 to 6.2.15
From 6.3 to 6.3.2
Configuration B
5 vulnerable
Vulnerable SoftwareAffected Versions
All versions
All versions
All versions
All versions
All versions

References (8)

Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Issue TrackingPatchThird Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
PatchThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party AdvisoryVDB Entry

Timeline

No history available yet.