CVE-2023-32247: Linux Kernel ksmbd Session Setup Memory Exhaustion Denial-of-Service Vulnerability
A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within the handling of SMB2SESSIONSETUP commands. The issue results from the lack of control of resource consumption. An attacker can leverage this vulnerability to create a denial-of-service condition on the system.
Other sources
A memory exhaustion issue was found in ksmbd, a high-performance in-kernel SMB server. Quoting ZDI security advisory [1]:
"This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Linux Kernel. Authentication is not required to exploit this vulnerability, but only systems with ksmbd enabled are vulnerable.
The specific flaw exists within the handling of SMB2SESSIONSETUP commands. The issue results from the lack of control of resource consumption. An attacker can leverage this vulnerability to create a denial-of-service condition on the system."
[1] https://www.zerodayinitiative.com/advisories/ZDI-CAN-20478/
— Red Hat
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2023-32247?
CVE-2023-32247 has been rated as high severity due to its potential for resource exhaustion and denial of service attacks.
How do I fix CVE-2023-32247?
To mitigate CVE-2023-32247, update the Linux kernel to version 6.4 or apply appropriate patches provided by your distribution.
What versions of the Linux kernel are affected by CVE-2023-32247?
CVE-2023-32247 affects Linux kernel versions between 5.15.0 and 6.3.9, and also some specific versions of minor releases.
Can CVE-2023-32247 be exploited remotely?
Yes, an attacker can exploit CVE-2023-32247 remotely through specially crafted SMB2_SESSION_SETUP commands.
Which Linux distributions are impacted by CVE-2023-32247?
CVE-2023-32247 impacts multiple Linux distributions that utilize the affected kernel versions, including those based on Red Hat and Debian.