CVE-2023-32252: Linux Kernel

High severity, CVSS 7.5. EPSS: 4.1% chance of exploitation in the next 30 days.

A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within the handling of SMB2_LOGOFF commands. The issue results from the lack of proper validation of a pointer prior to accessing it. An attacker can leverage this vulnerability to create a denial-of-service condition on the system.

Affected products

  • Linux Linux Kernel: from 5.15, before 5.15.145 (fixed in 5.15.145); from 5.16, before 6.1.29 (fixed in 6.1.29); from 6.2, before 6.2.16 (fixed in 6.2.16); from 6.3, before 6.3.2 (fixed in 6.3.2)
  • Netapp h300s Firmware: affected versions not specified
  • Netapp h410c Firmware: affected versions not specified
  • Netapp h410s Firmware: affected versions not specified
  • Netapp h500s Firmware: affected versions not specified
  • Netapp h700s Firmware: affected versions not specified

Published 2023-07-24. Last modified 2026-06-17.