New Linux kernel SMB security flaw revealed (2024)

New Linux kernel SMB security flaw revealed (1)

Tux

Ksmbd, introduced to the kernel in 2021, was developed by Samsung. Its goal was to deliver speedy SMB3 file-serving performance. SMB is used in Windows and Linux--via Samba--as an important file server protocol. Most distributions do not have Ksmbd compiled into the kernel or enabled by default.

But, if you have it in your kernel and enabled, pay attention. CVE-2023-0210 is a hole in the program's New Technology LAN Manager (NTLM) authentication. A knowledgeable attacker, with remote access to the server and a valid user name, could abuse it to overflow the allocated heap buffer.

This overflow, according to Sysdig, is too large to be used for remote code exploitation. That's the good news. The bad news is it can still cause a kernel panic, which would cause a denial of service.

Who wants a crashed server? I don't.

Still, Red Hat gives CVE-2023-0210 a Common Vulnerability Scoring System (CVSS) rating of 5.9, which is important, but far from critical. No Red Hat Enterprise Linux (RHEL) version, by the by, has this bug.

It gets such a comparatively low rating because to exploit, you must have KSMBD enabled. Since it's deployed in a module, you must enable and configure Ksmbd yourself. That's not a trivial job. Besides, only a security idiot exposes SMB port, 455, to the Internet, since, with its access to file systems, it's just asking to be attacked.

If you are using it, upgrade to the newly released Linux Kernel 6.2 RC4 or higher.

It's important to note that this problem has nothing to do with Samba, which is commonly used on Linux desktops and file servers. As Jeremy Allison, Samba's co-creator, told me about the earlier, more serious, hole, "ksmbd shares no code with production Samba. It's completely from scratch. So, this current situation has nothing to do with the Samba file server you may be running on your systems." The same is true of this vulnerability.

Personally, I'd steer clear of ksmbd for now. It may be faster than Samba, but two security problems in a row are two too many. And, besides, Samba's been battle-tested for over 30 years. I know which one I'm trusting on my production servers.

Other noteworthy Linux and open-source stories:

New Linux kernel SMB security flaw revealed (2024)
Top Articles
Getting started with SSH | Cloud Platform
Best Ways to Cut Costs After Retirement
Scheelzien, volwassenen - Alrijne Ziekenhuis
Golden Abyss - Chapter 5 - Lunar_Angel
NYT Mini Crossword today: puzzle answers for Tuesday, September 17 | Digital Trends
7 Verification of Employment Letter Templates - HR University
Gabrielle Abbate Obituary
Dee Dee Blanchard Crime Scene Photos
South Carolina defeats Caitlin Clark and Iowa to win national championship and complete perfect season
Puretalkusa.com/Amac
Urban Dictionary Fov
Craigslist Pets Longview Tx
Costco Gas Foster City
Mills and Main Street Tour
7543460065
Interactive Maps: States where guns are sold online most
111 Cubic Inch To Cc
Jinx Chapter 24: Release Date, Spoilers & Where To Read - OtakuKart
Comics Valley In Hindi
Walgreens San Pedro And Hildebrand
Cta Bus Tracker 77
Shiftselect Carolinas
Dragger Games For The Brain
Okc Body Rub
Shreveport City Warrants Lookup
Nsa Panama City Mwr
Dark Entreaty Ffxiv
Target Minute Clinic Hours
Piri Leaked
Mdt Bus Tracker 27
Xxn Abbreviation List 2017 Pdf
Japanese Emoticons Stars
Lininii
Bfri Forum
Basil Martusevich
LEGO Star Wars: Rebuild the Galaxy Review - Latest Animated Special Brings Loads of Fun With An Emotional Twist
Beth Moore 2023
Desirulez.tv
Indiana Wesleyan Transcripts
Bay Focus
Whitehall Preparatory And Fitness Academy Calendar
Dynavax Technologies Corp (DVAX)
Albertville Memorial Funeral Home Obituaries
Dwc Qme Database
2017 Ford F550 Rear Axle Nut Torque Spec
Unblocked Games - Gun Mayhem
Cara Corcione Obituary
9294027542
Great Clips Virginia Center Commons
Gummy Bear Hoco Proposal
David Turner Evangelist Net Worth
Acellus Grading Scale
Latest Posts
Article information

Author: Zonia Mosciski DO

Last Updated:

Views: 5926

Rating: 4 / 5 (51 voted)

Reviews: 90% of readers found this page helpful

Author information

Name: Zonia Mosciski DO

Birthday: 1996-05-16

Address: Suite 228 919 Deana Ford, Lake Meridithberg, NE 60017-4257

Phone: +2613987384138

Job: Chief Retail Officer

Hobby: Tai chi, Dowsing, Poi, Letterboxing, Watching movies, Video gaming, Singing

Introduction: My name is Zonia Mosciski DO, I am a enchanting, joyous, lovely, successful, hilarious, tender, outstanding person who loves writing and wants to share my knowledge and understanding with you.