ZeroHour
ZDI Published Advisoriespublished ()ingested 1

ZDI-26-693: Linux Kernel ksmbd Share Configuration Race Condition Remote Code Execution Vulnerability

highVulnerabilityimportance 45
AI summary · glm-5.3

ZDI-26-693: authenticated race condition in Linux kernel ksmbd share configuration allows remote code execution on ksmbd-enabled systems; CVSS 8.5.

ZDI advisory ZDI-26-693 discloses a race condition in the Linux kernel's ksmbd share configuration that allows remote attackers to execute arbitrary code on affected installations. Exploitation requires authentication, and only systems with ksmbd enabled are vulnerable. ZDI assigned a CVSS rating of 8.5; no CVE is listed in the advisory text.

  • Race condition in Linux kernel ksmbd share configuration
  • Authenticated remote attackers can execute arbitrary code
  • Only systems with ksmbd enabled are vulnerable
  • CVSS 8.5; no CVE listed in advisory
Full article

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Linux Kernel. Authentication is required to exploit this vulnerability. Furthermore, only systems with ksmbd enabled are vulnerable. The ZDI has assigned a CVSS rating of 8.5.

This source does not provide full text. Read it at zerodayinitiative.com.