Executive brief
A vulnerability in the Linux kernel's ksmbd component, which provides file sharing services, can allow an attacker to crash or slow down a server. By sending specific network traffic, an unauthenticated user can cause the system to exhaust its memory or enter an infinite loop. This results in a denial-of-service condition, making the system unavailable for legitimate business operations.
Technical details
A flaw exists in the ksmbd (SMB server) component of the Linux kernel within the ksmbd_conn_handler_loop() function. The vulnerability is characterized by a lack of memory release after its effective lifetime and a loop with an unreachable exit condition (CWE-835). An unauthenticated remote attacker can exploit this by initiating new TCP connections that trigger the infinite loop or memory leak, leading to system resource exhaustion. The issue was addressed in the Linux kernel 6.2-rc3 release.
Affected products
- Linux Linux Kernel versions before 6.2-rc3
Timeline
- 2023-01-01: patched: Fix committed to ksmbd git repository
- 2025-07-30: disclosed: NVD publication date
References
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/
- https://access.redhat.com/downloads/content/package-browser/
- https://access.redhat.com/security/cve/CVE-2023-2593
- https://bugzilla.redhat.com/show_bug.cgi?id=2384787
- https://lore.kernel.org/lkml/CAH2r5msyEy20e=FBx6wPWWc3kXzNR4b+zHshSqidRdFKVf_7Jg@mail.gmail.com/