Skip to main content

Race Condition During Access to Alternate Channel

CVE-2023-32256

Severity High
Score 7.5/10

Summary

A flaw was found in the Linux kernel's ksmbd component. A race condition between smb2 close operation and logoff in multichannel connections could result in a use-after-free issue.

  • HIGH
  • NETWORK
  • NONE
  • CHANGED
  • NONE
  • NONE
  • LOW
  • HIGH

CWE-421 - Race Condition During Access to Alternate Channel

The product opens an alternate channel to communicate with an authorized user, but the channel is accessible to other actors.

References

Advisory Timeline

  • Published