Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9qrv-rvg6-cq37

Опубликовано: 18 нояб. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 4

Описание

A flaw was found within the handling of SMB2_READ commands in the kernel ksmbd module. The issue results from not releasing memory after its effective lifetime. An attacker can leverage this to create a denial-of-service condition on affected installations of Linux. Authentication is not required to exploit this vulnerability, but only systems with ksmbd enabled are vulnerable.

A flaw was found within the handling of SMB2_READ commands in the kernel ksmbd module. The issue results from not releasing memory after its effective lifetime. An attacker can leverage this to create a denial-of-service condition on affected installations of Linux. Authentication is not required to exploit this vulnerability, but only systems with ksmbd enabled are vulnerable.

EPSS

Процентиль: 19%
0.00059
Низкий

4 Medium

CVSS3

Дефекты

CWE-125
CWE-400

Связанные уязвимости

CVSS3: 4
ubuntu
около 1 года назад

A flaw was found within the handling of SMB2_READ commands in the kernel ksmbd module. The issue results from not releasing memory after its effective lifetime. An attacker can leverage this to create a denial-of-service condition on affected installations of Linux. Authentication is not required to exploit this vulnerability, but only systems with ksmbd enabled are vulnerable.

CVSS3: 4
redhat
больше 1 года назад

A flaw was found within the handling of SMB2_READ commands in the kernel ksmbd module. The issue results from not releasing memory after its effective lifetime. An attacker can leverage this to create a denial-of-service condition on affected installations of Linux. Authentication is not required to exploit this vulnerability, but only systems with ksmbd enabled are vulnerable.

CVSS3: 4
nvd
около 1 года назад

A flaw was found within the handling of SMB2_READ commands in the kernel ksmbd module. The issue results from not releasing memory after its effective lifetime. An attacker can leverage this to create a denial-of-service condition on affected installations of Linux. Authentication is not required to exploit this vulnerability, but only systems with ksmbd enabled are vulnerable.

CVSS3: 4
debian
около 1 года назад

A flaw was found within the handling of SMB2_READ commands in the kern ...

CVSS3: 4
fstec
больше 2 лет назад

Уязвимость функции smb2_read() модуля fs/smb/server/smb2pdu.c подсистемы SMB ядра операционной системы Linux, позволяющая удаленному нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 19%
0.00059
Низкий

4 Medium

CVSS3

Дефекты

CWE-125
CWE-400