Linux Kernel ksmbd Path Handling Vulnerability in VFS Function

Vulnerability

A vulnerability in the Linux kernel's ksmbd component was introduced in version 6.1.0-rc1. The issue arises in the 'ksmbd_vfs_kern_path_locked' function, where an error can cause the function to exit prematurely without restoring the original path buffer. This unaddressed change can lead to incorrect path information being used, potentially allowing for unintended file operations.

Impact

Exploitation of this vulnerability could result in file operations being performed with incorrect path information, potentially leading to unintended file creation or modification.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
0.0
exploitability
5.3
remediation
0.0
relevance
0.0
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.