Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-39180

Опубликовано: 18 нояб. 2024
Источник: nvd
CVSS3: 4
CVSS3: 7.5
EPSS Низкий

Описание

A flaw was found within the handling of SMB2_READ commands in the kernel ksmbd module. The issue results from not releasing memory after its effective lifetime. An attacker can leverage this to create a denial-of-service condition on affected installations of Linux. Authentication is not required to exploit this vulnerability, but only systems with ksmbd enabled are vulnerable.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*

EPSS

Процентиль: 19%
0.00059
Низкий

4 Medium

CVSS3

7.5 High

CVSS3

Дефекты

CWE-400
CWE-125

Связанные уязвимости

CVSS3: 4
ubuntu
около 1 года назад

A flaw was found within the handling of SMB2_READ commands in the kernel ksmbd module. The issue results from not releasing memory after its effective lifetime. An attacker can leverage this to create a denial-of-service condition on affected installations of Linux. Authentication is not required to exploit this vulnerability, but only systems with ksmbd enabled are vulnerable.

CVSS3: 4
redhat
больше 1 года назад

A flaw was found within the handling of SMB2_READ commands in the kernel ksmbd module. The issue results from not releasing memory after its effective lifetime. An attacker can leverage this to create a denial-of-service condition on affected installations of Linux. Authentication is not required to exploit this vulnerability, but only systems with ksmbd enabled are vulnerable.

CVSS3: 4
debian
около 1 года назад

A flaw was found within the handling of SMB2_READ commands in the kern ...

CVSS3: 4
github
около 1 года назад

A flaw was found within the handling of SMB2_READ commands in the kernel ksmbd module. The issue results from not releasing memory after its effective lifetime. An attacker can leverage this to create a denial-of-service condition on affected installations of Linux. Authentication is not required to exploit this vulnerability, but only systems with ksmbd enabled are vulnerable.

CVSS3: 4
fstec
больше 2 лет назад

Уязвимость функции smb2_read() модуля fs/smb/server/smb2pdu.c подсистемы SMB ядра операционной системы Linux, позволяющая удаленному нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 19%
0.00059
Низкий

4 Medium

CVSS3

7.5 High

CVSS3

Дефекты

CWE-400
CWE-125