ZDI-24-1726: Linux Kernel ksmbd TCP Connection Memory Exhaustion Denial-of-Service Vulnerability
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of the Linux Kernel. Authentication is not required to exploit this vulnerability. However, only systems with ksmbd enabled are vulnerable. The ZDI has assigned a CVSS rating of 5.9. The following CVEs are assigned: CVE-2024-50285.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-24-1726?
ZDI-24-1726 has a CVSS rating indicating it presents a high severity risk as it can lead to denial-of-service conditions.
How do I fix ZDI-24-1726?
To fix ZDI-24-1726, update your Linux Kernel to a version where the vulnerability is patched and ensure that ksmbd is configured properly.
Who is affected by ZDI-24-1726?
Only systems with the ksmbd feature enabled in the Linux Kernel are affected by ZDI-24-1726.
Can ZDI-24-1726 be exploited remotely?
Yes, ZDI-24-1726 allows remote attackers to exploit the vulnerability without requiring authentication.
What type of attack does ZDI-24-1726 facilitate?
ZDI-24-1726 facilitates a denial-of-service attack, potentially disrupting the availability of the affected system.