Impact
The vulnerability in the ksmbd module permits write‑capable users to escape the share root and create zero‑length files or directories outside the exported share. This bypass arises when the system incorrectly retries caseless lookups after a -EXDEV error, allowing a crafted path containing '..' components to be resolved beyond the intended boundary.
Affected Systems
The flaw exists in the Linux kernel’s ksmbd component, affecting any distribution that includes ksmbd before the patch. The affected product is the Linux kernel; no specific version range is listed, so all kernels compiled with ksmbd prior to the fix are vulnerable.
Risk and Exploitability
This vulnerability has a CVSS score of 8.6, while its EPSS score is below 1%, indicating that exploitation is unlikely but still possible. The vulnerability is not in CISA’s KEV list and no public exploit is known. An attacker would need write access to an SMB share and be able to send a crafted path with '..' components. The likely attack vector is a SMB client with write privileges, potentially enabling the creator of critical system files if the share overlaps the file system.
OpenCVE Enrichment