Impact
This vulnerability is an invalid pointer dereference in the Linux kernel SMB server routine ksmbd_stop_durable_scavenger. The flaw can trigger a kernel panic when the SMB server attempts to stop a scavenger thread that failed to start, resulting in a complete system outage. The weakness is a pointer dereference error (CWE-665).
Affected Systems
The flaw is in the generic Linux kernel, affecting any Linux distribution that ships an unpatched kernel version before the commit that fixes ksmbd_stop_durable_scavenger. Versions prior to that commit are vulnerable. The CNA lists the vendor as Linux:Linux.
Risk and Exploitability
The EPSS score is less than 1%, indicating a very low probability of exploitation in the wild, and the flaw is not listed in CISA’s KEV catalog. No CVSS score is present, but a kernel panic represents a severe impact. Attackers would need to trigger the conditions that cause the scavenger thread to fail then invoke a server reset, which is likely local or remote with sufficient privileges to execute SMB server operations; (Inferred from the description). Exploitation complexity remains high. Overall risk is moderate due to low exploit likelihood but high potential impact if exploited.
OpenCVE Enrichment
Debian DLA
Debian DSA