New Linux kernel SMB security flaw revealed (2024)

New Linux kernel SMB security flaw revealed (1)

Tux

Ksmbd, introduced to the kernel in 2021, was developed by Samsung. Its goal was to deliver speedy SMB3 file-serving performance. SMB is used in Windows and Linux--via Samba--as an important file server protocol. Most distributions do not have Ksmbd compiled into the kernel or enabled by default.

But, if you have it in your kernel and enabled, pay attention. CVE-2023-0210 is a hole in the program's New Technology LAN Manager (NTLM) authentication. A knowledgeable attacker, with remote access to the server and a valid user name, could abuse it to overflow the allocated heap buffer.

This overflow, according to Sysdig, is too large to be used for remote code exploitation. That's the good news. The bad news is it can still cause a kernel panic, which would cause a denial of service.

Who wants a crashed server? I don't.

Still, Red Hat gives CVE-2023-0210 a Common Vulnerability Scoring System (CVSS) rating of 5.9, which is important, but far from critical. No Red Hat Enterprise Linux (RHEL) version, by the by, has this bug.

It gets such a comparatively low rating because to exploit, you must have KSMBD enabled. Since it's deployed in a module, you must enable and configure Ksmbd yourself. That's not a trivial job. Besides, only a security idiot exposes SMB port, 455, to the Internet, since, with its access to file systems, it's just asking to be attacked.

If you are using it, upgrade to the newly released Linux Kernel 6.2 RC4 or higher.

It's important to note that this problem has nothing to do with Samba, which is commonly used on Linux desktops and file servers. As Jeremy Allison, Samba's co-creator, told me about the earlier, more serious, hole, "ksmbd shares no code with production Samba. It's completely from scratch. So, this current situation has nothing to do with the Samba file server you may be running on your systems." The same is true of this vulnerability.

Personally, I'd steer clear of ksmbd for now. It may be faster than Samba, but two security problems in a row are two too many. And, besides, Samba's been battle-tested for over 30 years. I know which one I'm trusting on my production servers.

Other noteworthy Linux and open-source stories:

New Linux kernel SMB security flaw revealed (2024)
Top Articles
Shifting From Paper To Digital: The Pros and Cons — Tricostar
Federal Reserve - Frequently Asked Questions (FAQs)
Katie Pavlich Bikini Photos
Gamevault Agent
Hocus Pocus Showtimes Near Harkins Theatres Yuma Palms 14
Free Atm For Emerald Card Near Me
Craigslist Mexico Cancun
Hendersonville (Tennessee) – Travel guide at Wikivoyage
Doby's Funeral Home Obituaries
Vardis Olive Garden (Georgioupolis, Kreta) ✈️ inkl. Flug buchen
Select Truck Greensboro
Things To Do In Atlanta Tomorrow Night
Non Sequitur
How To Cut Eelgrass Grounded
Pac Man Deviantart
Alexander Funeral Home Gallatin Obituaries
Craigslist In Flagstaff
Shasta County Most Wanted 2022
Energy Healing Conference Utah
Testberichte zu E-Bikes & Fahrrädern von PROPHETE.
Aaa Saugus Ma Appointment
Geometry Review Quiz 5 Answer Key
Walgreens Alma School And Dynamite
Bible Gateway passage: Revelation 3 - New Living Translation
Yisd Home Access Center
Home
Shadbase Get Out Of Jail
Gina Wilson Angle Addition Postulate
Celina Powell Lil Meech Video: A Controversial Encounter Shakes Social Media - Video Reddit Trend
Walmart Pharmacy Near Me Open
A Christmas Horse - Alison Senxation
Ou Football Brainiacs
Access a Shared Resource | Computing for Arts + Sciences
Pixel Combat Unblocked
Cvs Sport Physicals
Mercedes W204 Belt Diagram
Rogold Extension
'Conan Exiles' 3.0 Guide: How To Unlock Spells And Sorcery
Teenbeautyfitness
Where Can I Cash A Huntington National Bank Check
Facebook Marketplace Marrero La
Nobodyhome.tv Reddit
Topos De Bolos Engraçados
Gregory (Five Nights at Freddy's)
Grand Valley State University Library Hours
Holzer Athena Portal
Hampton In And Suites Near Me
Stoughton Commuter Rail Schedule
Bedbathandbeyond Flemington Nj
Free Carnival-themed Google Slides & PowerPoint templates
Otter Bustr
Selly Medaline
Latest Posts
Article information

Author: Zonia Mosciski DO

Last Updated:

Views: 5926

Rating: 4 / 5 (51 voted)

Reviews: 90% of readers found this page helpful

Author information

Name: Zonia Mosciski DO

Birthday: 1996-05-16

Address: Suite 228 919 Deana Ford, Lake Meridithberg, NE 60017-4257

Phone: +2613987384138

Job: Chief Retail Officer

Hobby: Tai chi, Dowsing, Poi, Letterboxing, Watching movies, Video gaming, Singing

Introduction: My name is Zonia Mosciski DO, I am a enchanting, joyous, lovely, successful, hilarious, tender, outstanding person who loves writing and wants to share my knowledge and understanding with you.