#VU77498 Race condition in Linux kernel - CVE-2023-32254
Published: June 19, 2023
Linux kernel
Linux Foundation
Description
The vulnerability allows a remote attacker to execute arbitrary code on the system.
The vulnerability exists due to a race condition within fs/ksmbd/mgmt/tree_connect.c in ksmbd in Linux kernel when processing SMB2_TREE_DISCONNECT commands. A remote attacker can trigger a use-after-free error using concurrent smb2 tree disconnect requests and execute arbitrary code on the system.