Junglewise Threat Intelligence

CVE-2023-32256: Linux Kernel ksmbd use-after-free in SMB2 close and logoff

CVE-2023-32256 · Severity: high · CVSS 7.5 · Published 2025-08-01

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A security vulnerability has been identified in the Linux kernel's ksmbd component, which provides file-sharing services over a network. Under specific conditions involving multiple simultaneous connections, an attacker could cause a system crash or potentially gain unauthorized access to memory. This issue primarily affects organizations using the ksmbd module for high-performance file sharing in Linux environments.

Technical details

A race condition exists in the ksmbd component of the Linux kernel when handling concurrent SMB2_CLOSE and SMB2_LOGOFF requests over multichannel connections. The flaw stems from a lack of proper locking and synchronization; specifically, a logoff request can free a tree connection (tcon) object while a simultaneous close operation is still accessing it, leading to a use-after-free (UAF) condition. This vulnerability can be triggered remotely without authentication if ksmbd is enabled. An attacker could exploit this to cause a kernel oops (denial of service) or potentially achieve arbitrary code execution in the context of the kernel. The issue has been addressed in the Linux kernel by ensuring ksmbd waits for all remaining requests to complete before expiring a session.

Affected products

  • Linux Linux Kernel 5.15.145, 6.1.29, 6.2.16, 6.3.2

Timeline

  • 2023-05-03: patched: Fix committed to Linux kernel source tree
  • 2025-08-01: disclosed: CVE published and Red Hat advisory issued

References

Related threats