Linux Kernel Security Update 25 December 2022

Linux kernel is affected by a critical issue in ksmbd before version 5.19.2.

KSMBD is a Linux kernel server that implements SMB3 protocol in kernel space for sharing files over the network.

The severity of the mentioned vulnerability could allow the remote attacker to execute code on the affected systems.

Linux Kernel Ksmbd Use-After-Free Remote Code Execution (CVE-2022-47939):

• CVSS: 10

• Attack Vector: Network

• Attack Complexity: Low

• Privileges Required: Low

• User Interaction: None

• Consequences: Gain Access

Vulnerabilities
  • CVE-2022-47939
Mitigations

The enterprise should deploy the patches as soon as the testing phase is completed, and should check with its vendors for updates, if any. Below is a sample of the distributors’ fixes:

SUSE Updates

Ubuntu Updates

Redhat Updates

References