ZDI-24-1456: Linux Kernel ksmbd Session Race Condition Remote Code Execution Vulnerability
Published Nov 5, 2024
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Linux Kernel. Authentication is required to exploit this vulnerability. However, only systems with ksmbd enabled are vulnerable. The ZDI has assigned a CVSS rating of 8.5.
Affected Software
1 affected component
Linux Kernel
Event History
Nov 5, 2024
Advisory Published
via ZDI·06:00 AM
Data Sourced
via ZDI·06:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-24-1456?
ZDI-24-1456 has a CVSS severity rating of 8.5, indicating a high level of risk.
2
How do I fix ZDI-24-1456?
To mitigate ZDI-24-1456, users should update the Linux Kernel to a patched version that addresses the ksmbd session race condition.
3
What systems are affected by ZDI-24-1456?
ZDI-24-1456 affects installations of Linux Kernel where ksmbd is enabled.
4
What type of attack does ZDI-24-1456 enable?
ZDI-24-1456 allows remote attackers to execute arbitrary code on the affected systems.
5
Is authentication needed to exploit ZDI-24-1456?
Yes, authentication is required to exploit the ZDI-24-1456 vulnerability.