CVE-2022-47941: Linux Kernel ksmbd Memory Exhaustion Denial-of-Service Vulnerability
An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.19 before 5.19.2. fs/ksmbd/smb2pdu.c omits a kfree call in certain smb2handlenegotiate error conditions, aka a memory leak.
Other sources
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Linux Kernel. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of SMB2NEGOTIATE commands. The issue results from the lack of memory release after its effective lifetime. An attacker can leverage this vulnerability to create a denial-of-service condition on the system.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-47941?
CVE-2022-47941 is a vulnerability in the Linux Kernel that allows remote attackers to create a denial-of-service condition.
Is authentication required to exploit CVE-2022-47941?
No, authentication is not required to exploit CVE-2022-47941.
What is the severity of CVE-2022-47941?
The severity of CVE-2022-47941 is high, with a CVSS score of 7.5.
Which versions of Linux Kernel are affected by CVE-2022-47941?
Versions of Linux Kernel between 5.15 and 5.15.61, between 5.16 and 5.18.18, and between 5.19 and 5.19.2 are affected by CVE-2022-47941.
How can I fix CVE-2022-47941?
To fix CVE-2022-47941, update your Linux Kernel to a version that is not affected by the vulnerability.