Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-54162

Опубликовано: 30 дек. 2025
Источник: redhat
CVSS3: 7.5

Описание

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix possible memory leak in smb2_lock() argv needs to be free when setup_async_work fails or when the current process is woken up.

A flaw was found in ksmbd, a Linux kernel module that provides an in-kernel SMB server. This vulnerability involves a possible memory leak within the smb2_lock() function. The memory allocated for argv is not properly freed if the setup_async_work operation fails or if the current process is woken up. This oversight could allow a local attacker to cause a denial of service (DoS) by exhausting system memory.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10kernelNot affected
Red Hat Enterprise Linux 6kernelNot affected
Red Hat Enterprise Linux 7kernelNot affected
Red Hat Enterprise Linux 7kernel-rtNot affected
Red Hat Enterprise Linux 8kernelNot affected
Red Hat Enterprise Linux 8kernel-rtNot affected
Red Hat Enterprise Linux 9kernelNot affected
Red Hat Enterprise Linux 9kernel-rtNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-772
https://bugzilla.redhat.com/show_bug.cgi?id=2426127kernel: ksmbd: Denial of Service via memory leak in smb2_lock()

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
8 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix possible memory leak in smb2_lock() argv needs to be free when setup_async_work fails or when the current process is woken up.

CVSS3: 8.8
nvd
8 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix possible memory leak in smb2_lock() argv needs to be free when setup_async_work fails or when the current process is woken up.

CVSS3: 8.8
debian
8 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: k ...

CVSS3: 8.8
github
8 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix possible memory leak in smb2_lock() argv needs to be free when setup_async_work fails or when the current process is woken up.

CVSS3: 5.9
fstec
больше 3 лет назад

Уязвимость функции smb2_lock() ядра операционной системы Linux, позволяющая нарушителю вызвать отказ в обслуживании

7.5 High

CVSS3