Impact
The Linux kernel’s ksmbd component allows an authenticated client to send numerous structurally valid but unmapped Security Identifiers (SIDs) in a DAccess Control List (DACL). Each unmapped SID triggers a kernel error log entry. When the rate limiting for these log messages is removed, a single request can produce hundreds of error logs, potentially exhausting kernel log buffers and degrading system performance. The vulnerability does not grant arbitrary code execution or privilege escalation, but it can disrupt normal operation by flooding the kernel log and exhausting log space.
Affected Systems
This flaw exists in the Linux kernel. No specific kernel version is listed in the advisory, so any kernel that implements ksmbd and lacks the recent rate‑limiting fix is potentially affected. The vulnerability is vendor‑agnostic, affecting all distributions that ship the unpatched kernel.
Risk and Exploitability
The CVE is not listed in CISA’s KEV catalog and the EPSS score is unavailable, indicating that the likelihood of exploitation is not well established. Nevertheless, because the attack requires an authenticated client, an insider or compromised user could intentionally flood logs to cause denial of service. The impact on availability could be significant on low‑resource or high‑security systems where log space is constrained. The absence of a publicly known CVSS score makes formal severity assessment incomplete, but the potential for resource exhaustion makes this a high‑risk item for administrators who depend on kernel log stability.
OpenCVE Enrichment