CVE-2023-39180: Linux Kernel
High severity, CVSS 7.5. EPSS: 1.4% chance of exploitation in the next 30 days.
A flaw was found within the handling of SMB2_READ commands in the kernel ksmbd module. The issue results from not releasing memory after its effective lifetime. An attacker can leverage this to create a denial-of-service condition on affected installations of Linux. Authentication is not required to exploit this vulnerability, but only systems with ksmbd enabled are vulnerable.
Affected products
- Linux Linux Kernel: affected versions not specified
Published 2024-11-18. Last modified 2026-06-17.