CVE-2023-32247: Linux Kernel
High severity, CVSS 7.5. EPSS: 3.9% chance of exploitation in the next 30 days.
A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within the handling of SMB2_SESSION_SETUP commands. The issue results from the lack of control of resource consumption. An attacker can leverage this vulnerability to create a denial-of-service condition on the system.
Affected products
- Linux Linux Kernel: from 5.15, before 5.15.145 (fixed in 5.15.145); from 5.16, before 6.1.29 (fixed in 6.1.29); from 6.2, before 6.2.16 (fixed in 6.2.16); from 6.3, before 6.3.2 (fixed in 6.3.2)
- Netapp h300s: affected versions not specified
- Netapp h410s: affected versions not specified
- Netapp h500s: affected versions not specified
- Netapp h700s: affected versions not specified
Published 2023-07-24. Last modified 2026-06-17.