ZDI-CAN-20592: ZDI-23-702: Linux Kernel ksmbd Tree Connection Race Condition Remote Code Execution Vulnerability
Published May 17, 2023
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Linux Kernel. Authentication is not required to exploit this vulnerability, but only systems with ksmbd enabled are vulnerable.
Affected Software
1 affected component
Linux Kernel
Event History
May 17, 2023
Advisory Published
05:00 AM
Data Sourced
05:00 AM
Description
Feb 26, 2025
Advisory Published
via ZDI·03:45 PM
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is ZDI-CAN-20592.
2
What is the title of the vulnerability?
The title of the vulnerability is ZDI-23-702: Linux Kernel ksmbd Tree Connection Race Condition Remote Code Execution Vulnerability.
3
What is the severity of the vulnerability?
The severity of the vulnerability is critical with a severity value of 9.
4
Which systems are affected by this vulnerability?
Only systems with ksmbd enabled are vulnerable.
5
Is authentication required to exploit this vulnerability?
No, authentication is not required to exploit this vulnerability.
6
Is there a fix available for this vulnerability?
Yes, a fix for this vulnerability is available. Please refer to the provided references for more information.