Linux Kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A remote code execution vulnerability has been identified in the Linux kernel's ksmbd component, specifically within the session setup process. This issue arises from improper locking during session lookup, leading to a race condition where an attacker can exploit the vulnerability to execute arbitrary code in the kernel's context. The vulnerability affects systems with ksmbd enabled, and does not require authentication to exploit.
Exploitation of this vulnerability allows remote attackers to execute arbitrary code on the affected system with kernel-level privileges.
Linux has released a patch for this vulnerability. Details about the patch can be found in the Linux kernel's stable queue repository.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.