A vulnerability has been identified in the Linux kernel's ksmbd component (kernel SMB/CIFS server). A security control designed to prevent dictionary attacks, which introduces a 5-second delay during session setup, can be bypassed through the use of asynchronous requests. This bypass negates the intended anti-brute-force protection, potentially allowing attackers to conduct dictionary attacks more efficiently against user credentials or other authentication mechanisms.
[
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@b096d97f47326b1e2dbdef1c91fab69ffda54d17",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"digest": {
"function_hash": "164569407749625159246971409386769825941",
"length": 4818.0
},
"target": {
"function": "smb2_sess_setup",
"file": "fs/ksmbd/smb2pdu.c"
},
"id": "CVE-2023-32251-810bf3f6"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@b096d97f47326b1e2dbdef1c91fab69ffda54d17",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"234722189736021925612120963561551430775",
"93160617462506858615454289338876849183",
"129820706034301252816886031266185623606",
"309770935352726325128239284822450187721",
"62561670358288608957035300517821575372"
]
},
"target": {
"file": "fs/ksmbd/smb2pdu.c"
},
"id": "CVE-2023-32251-ed64b767"
}
]