CVE-2022-47939 critical vulnerability in Linux kernel `ksmbd` module: everything you need to know
ID: 27759ce8-bba6-57fa-b951-1e9894bdbb6c
STIX ID: report--27759ce8-bba6-57fa-b951-1e9894bdbb6c
Feed Name: Wiz Blog
Threat Score
A critical remote code execution vulnerability (CVE-2022-47939) was identified in the Linux kernel ksmbd in-kernel SMB server (introduced in 5.15), allowing potential kernel-level code execution via malformed SMB2_TREE_DISCONNECT handling; the issue scores highly (ZDI CVSS 10.0) but exposure is limited because ksmbd is rarely enabled by default and a patch was released in Linux 5.15.61.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
