cbcvebase.
CVE-2023-52479
published 2024-02-29

CVE-2023-52479: In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix uaf in smb20_oplock_break_ack drop reference after use opinfo.

PriorityP426high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.23%
14.4th percentile
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix uaf in smb20_oplock_break_ack drop reference after use opinfo.

Affected

16 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.64-1 (bookworm)linux 6.1.64-1 (bookworm)
linuxlinux
linuxlinux>= 0626e6641f6b467447c81dd7678a69c66f7746cf < 694e13732e830cbbfedb562e57f28644927c33fd694e13732e830cbbfedb562e57f28644927c33fd
linuxlinux>= 0626e6641f6b467447c81dd7678a69c66f7746cf < 8226ffc759ea59f10067b9acdf7f94bae1c699308226ffc759ea59f10067b9acdf7f94bae1c69930
linuxlinux>= 0626e6641f6b467447c81dd7678a69c66f7746cf < d5b0e9d3563e7e314a850e81f42b2ef6f39882f9d5b0e9d3563e7e314a850e81f42b2ef6f39882f9
linuxlinux>= 0626e6641f6b467447c81dd7678a69c66f7746cf < c69813471a1ec081a0b9bf0c6bd7e8afd818afcec69813471a1ec081a0b9bf0c6bd7e8afd818afce
linuxlinux_kernel< 5.15.1355.15.135
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.64-16.1.64-1
linuxlinux_kernel>= 0 < 6.5.8-16.5.8-1
linuxlinux_kernel>= 0 < 6.5.8-16.5.8-1
linuxlinux_kernel>= 5.16 < 6.1.576.1.57
linuxlinux_kernel>= 6.2 < 6.5.76.5.7

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv7.1HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.