Cyber News / Article / CVE-2022-47939 critical vulnerability in Linux kernel `ksmbd` module: everything you need to know

CVE-2022-47939 critical vulnerability in Linux kernel `ksmbd` module: everything you need to know
Critical RCE vulnerability found in Linux kernel's `ksmbd` module: remote attackers can execute code without authentication. The module is not enabled by default on most operating systems.
A critical remote code execution vulnerability (CVE-2022-47939) has been identified in theksmbdmodule of the Linux kernel. This means that remote attackers could potentially execute arbitrary code on affected systems running the Linux kernel without requiring authentication. However, it's important to note this vulnerability is only exploitable on systems with theksmbdin-kernel module enabled. The vulnerability was first published as ZDI-22-1690 on December 22, 2022, by Zero Day Initiative and given a score of CVSS 10.0, before it was assigned a CVE.
Theksmbdmodule was only recently introduced in Linux5.15, so it is not yet widely used. As a result, exploitable systems are not common.
The vulnerability lies in theksmbdmodule, an in-kernel SMB file server that was introduced in Linux 5.15 release on August 29, 2021.
A bug was discovered in the waySMB2_TREE_DISCONNECTcommands are processed: the system does not verify whether an object exists before attempting to perform operations on it, allowing an attacker to potentially execute code with kernel-level privileges.
If you are using an SMB server with Samba, you are not affected by this vulnerability.
The vulnerableksmbdmodule is not enabled by default on most operating systems, so the likelihood of this vulnerability being exploited on most systems is relatively low. We can confirm according to Wiz data that systems utilizing this module are rare.
The vulnerability affects machines running Linux versions newer than5.15withksmbdenabled.
Impacted, fixed: Jammy 5.15.0-53.59 Kinetic 5.19.0-16.16
Impacted, fixed: Buster 4.19.249-2 Buster (security) 4.19.269-1 Bullseye 5.10.158-2 Bullseye (security) 5.10.149-2 Bookworm, sid 6.0.12-1
** Additional Ubuntu releases are vulnerable, please refer to thevendors advisoryfor the latest updates.
A patch was released in Linux version5.15.61that addresses this issue. To protect against exploitation of this vulnerability, it is advised to update to this version or a later one in order to fully mitigate the risk. Keeping your system up to date with the latest security patches is always a good practice to ensure the safety and security of your system.
Wiz customers can use the pre-built query and advisory in the Wiz Threat Center to search for vulnerable instances in their environment.
Zero-day initiative advisory
Ubuntu advisory
Debian advisory
Red Hat advisory
A new exploit method targeting CVE-2022-41080 and CVE-2022-41082 vulnerabilities in Exchange servers, which can bypass previous workarounds, has been discovered and exploited in the wild. Organizations should patch urgently.
Wiz enhances its Dynamic Scanner to detect publicly exposed, unauthenticated APIs
Easily detect dangling domains to reduce the risk of phishing campaigns and cookie harvesting of organization’s customers.
Get a personalized demo
©2026Wiz, Inc.
StatusPrivacy PolicyTerms of UseModern Slavery StatementCookie Settings
Related articles
Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code
6 days ago
Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root
8 days ago
SAP Patches Critical Extended Passport Processing Vulnerability
3 days ago
You might Also like

Chrome 153 Fixes 230 Vulnerabilities, Including One 0-Day Exploited in the Wild

N-able N-central Pre-Auth RCE Flaw Exploited in the Wild

