A flaw was found within the handling of SMB2_READ commands in the kernel ksmbd module. The issue results from not releasing memory after its effective lifetime. An attacker can leverage this to create a denial-of-service condition on affected installations of Linux. Authentication is not required to exploit this vulnerability, but only systems with ksmbd enabled are vulnerable.
Metrics
Affected Vendors & Products
References
History
Mon, 18 Nov 2024 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-125 | |
Metrics |
ssvc
|
Mon, 18 Nov 2024 10:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Title | kernel: ksmbd: Read Request Memory Leak Denial-of-Service Vulnerability | Kernel: ksmbd: read request memory leak denial-of-service vulnerability |
First Time appeared |
Redhat
Redhat enterprise Linux |
|
CPEs | cpe:/o:redhat:enterprise_linux:6 cpe:/o:redhat:enterprise_linux:7 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
Vendors & Products |
Redhat
Redhat enterprise Linux |
|
References |
|
Sat, 16 Nov 2024 03:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A flaw was found within the handling of SMB2_READ commands in the kernel ksmbd module. The issue results from not releasing memory after its effective lifetime. An attacker can leverage this to create a denial-of-service condition on affected installations of Linux. Authentication is not required to exploit this vulnerability, but only systems with ksmbd enabled are vulnerable. | |
Title | kernel: ksmbd: Read Request Memory Leak Denial-of-Service Vulnerability | |
Weaknesses | CWE-400 | |
References |
| |
Metrics |
threat_severity
|
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: fedora
Published: 2024-11-18T09:53:20.134Z
Updated: 2024-11-18T15:05:29.429Z
Reserved: 2023-07-25T15:45:06.863Z
Link: CVE-2023-39180
Vulnrichment
Updated: 2024-11-18T15:05:21.717Z
NVD
Status : Awaiting Analysis
Published: 2024-11-18T10:15:05.217
Modified: 2024-11-18T17:11:17.393
Link: CVE-2023-39180
Redhat