Junglewise Threat Intelligence

CVE-2023-32253: Linux Kernel denial of service in ksmbd session setup

CVE-2023-32253 · Severity: medium · CVSS 5.9 · Published 2025-08-02

Technologies: Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 10, Linux Kernel. Vendors: Red Hat, Linux.

Executive brief

A flaw in the Linux kernel's ksmbd component, which provides file sharing services, can allow a remote attacker to crash or freeze the system. By sending specific, simultaneous connection requests, an attacker can trigger a 'deadlock' that stops the server from responding. This results in a denial of service, impacting the availability of shared files and network operations.

Technical details

A flaw was found in the Linux kernel's ksmbd component (an in-kernel SMB server). The vulnerability is an improper resource locking issue (CWE-413) within the ksmbd_find_crypto_ctx() function during the processing of SMB2_SESSION_SETUP commands. A remote, unauthenticated attacker can trigger a deadlock by sending multiple concurrent session setup requests. This condition leads to a kernel hang or crash, resulting in a denial of service. The vulnerability affects various kernel versions including 5.15.x, 6.1.x, 6.2.x, and 6.3.x, and has been addressed in upstream stable releases.

Affected products

  • Linux Linux Kernel 5.15.112, 6.1.28, 6.2.15, 6.3.2
  • Red Hat Red Hat Enterprise Linux 10
  • Red Hat Red Hat Enterprise Linux 9

Timeline

  • 2025-08-01: disclosed: Initial bug report in Red Hat Bugzilla
  • 2025-08-02: advisory: NVD publication date

References

Related threats