Impact
A null pointer dereference occurs in the kernel's SMB (smbd) server when handling an IPC tree connect request. The failure to validate the return value of kstrdup() leaves a NULL share name unchecked, which the next call to strlen() crashes the kernel. This leads to a system‑wide crash and loss of service rather than execution of arbitrary code.
Affected Systems
The flaw is present in the Linux kernel’s smb server component (smbd) on any distribution that has not yet applied the fix. The specific kernel versions are not enumerated in the data, but all kernels containing the unpatched smbd module are affected.
Risk and Exploitability
An attacker could trigger the crash by initiating an IPC tree connect request over SMB, which is typically a remote attack vector. The EPSS score is less than 1%, suggesting a low exploitation likelihood, and the vulnerability is not listed in CISA’s KEV catalog. The impact is limited to denial of service because the flaw causes a kernel panic rather than granting code execution or elevated privileges.
OpenCVE Enrichment
Debian DLA
Debian DSA