ZDI-CAN-25738: ZDI-24-1726: Linux Kernel ksmbd TCP Connection Memory Exhaustion Denial-of-Service Vulnerability
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of the Linux Kernel. Authentication is not required to exploit this vulnerability. However, only systems with ksmbd enabled are vulnerable. The ZDI has assigned a CVSS rating of 5.9. The following CVEs are assigned: CVE-2024-50285.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-25738?
The severity of ZDI-CAN-25738 is rated at 5.9 according to CVSS.
How do I fix ZDI-CAN-25738?
To fix ZDI-CAN-25738, you should disable ksmbd if it is not needed or apply the latest security patches provided by the Linux Kernel maintainers.
What type of vulnerability is ZDI-CAN-25738?
ZDI-CAN-25738 is a denial-of-service vulnerability that can be exploited to exhaust memory on affected systems.
Who can exploit ZDI-CAN-25738?
Any remote attacker can exploit ZDI-CAN-25738 without requiring authentication, as long as ksmbd is enabled.
What systems are affected by ZDI-CAN-25738?
Only Linux Kernel installations with ksmbd enabled are affected by ZDI-CAN-25738.