UBUNTU-CVE-2023-32252
Dashboard / Vulnerabilities / UBUNTU-CVE-2023-32252
UBUNTU-CVE-2023-32252
Summary:
Details: A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within the handling of SMB2_LOGOFF commands. The issue results from the lack of proper validation of a pointer prior to accessing it. An attacker can leverage this vulnerability to create a denial-of-service condition on the system.
References: https://ubuntu.com/security/CVE-2023-32252, https://access.redhat.com/security/cve/CVE-2023-32252, https://www.zerodayinitiative.com/advisories/ZDI-CAN-20590/, https://ubuntu.com/security/notices/USN-6338-1, https://ubuntu.com/security/notices/USN-6344-1, https://ubuntu.com/security/notices/USN-6338-2, https://ubuntu.com/security/notices/USN-6626-1, https://ubuntu.com/security/notices/USN-6628-1, https://ubuntu.com/security/notices/USN-6626-2, https://ubuntu.com/security/notices/USN-6628-2, https://ubuntu.com/security/notices/USN-6626-3, https://www.cve.org/CVERecord?id=CVE-2023-32252
Affected packages
Package
Name: linux-hwe-edge
Purl: pkg:deb/ubuntu/linux-hwe-edge?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
