Impact
The vulnerability is an out‑of‑bounds read in the ksmbd kernel module caused by reading length fields from an unverified response buffer before verifying the buffer’s size. This flaw can expose sensitive kernel memory to an attacker or trigger a kernel panic. The issue is catalogued as CWE‑125, highlighting improper bounds checking of data derived from user input.
Affected Systems
All Linux kernel distributions that ship the ksmbd userspace daemon are affected. No specific firmware or kernel version is listed, so any currently supported kernel that has not yet applied the ksmbd patch is considered vulnerable.
Risk and Exploitability
The EPSS score of less than 1% and the absence from the CISA KEV list suggest a low probability of exploitation at this time. An attacker would need to send a crafted SMB or Netlink message to the ksmbd daemon, which could be performed remotely through SMB traffic or locally via a malicious client. While the flaw does not provide immediate remote code execution, it can lead to information disclosure, privilege escalation, or denial‑of‑service if an attacker can provoke a crash.
OpenCVE Enrichment
Debian DLA
Debian DSA