A flaw was found within the handling of SMB2_READ commands in the kernel ksmbd module. The issue results from not releasing memory after its effective lifetime. An attacker can leverage this to create a denial-of-service condition on affected installations of Linux. Authentication is not required to exploit this vulnerability, but only systems with ksmbd enabled are vulnerable.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 06 Aug 2025 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel

Mon, 18 Nov 2024 15:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 18 Nov 2024 10:00:00 +0000

Type Values Removed Values Added
Title kernel: ksmbd: Read Request Memory Leak Denial-of-Service Vulnerability Kernel: ksmbd: read request memory leak denial-of-service vulnerability
First Time appeared Redhat
Redhat enterprise Linux
CPEs cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
References

Sat, 16 Nov 2024 03:00:00 +0000

Type Values Removed Values Added
Description A flaw was found within the handling of SMB2_READ commands in the kernel ksmbd module. The issue results from not releasing memory after its effective lifetime. An attacker can leverage this to create a denial-of-service condition on affected installations of Linux. Authentication is not required to exploit this vulnerability, but only systems with ksmbd enabled are vulnerable.
Title kernel: ksmbd: Read Request Memory Leak Denial-of-Service Vulnerability
Weaknesses CWE-400
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.0, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:L'}

threat_severity

Low


cve-icon MITRE

Status: PUBLISHED

Assigner: fedora

Published:

Updated: 2024-11-18T15:05:29.429Z

Reserved: 2023-07-25T15:45:06.863Z

Link: CVE-2023-39180

cve-icon Vulnrichment

Updated: 2024-11-18T15:05:21.717Z

cve-icon NVD

Status : Analyzed

Published: 2024-11-18T10:15:05.217

Modified: 2025-08-06T13:34:08.167

Link: CVE-2023-39180

cve-icon Redhat

Severity : Low

Publid Date: 2024-06-10T00:00:00Z

Links: CVE-2023-39180 - Bugzilla

cve-icon OpenCVE Enrichment

No data.