logo

CVE-2022-47939 critical vulnerability in Linux kernel `ksmbd` module: everything you need to know

ID: 27759ce8-bba6-57fa-b951-1e9894bdbb6c

STIX ID: report--27759ce8-bba6-57fa-b951-1e9894bdbb6c

Feed Name: Wiz Blog

Threat Score
55/100

Date Published: 2022-12-27

Date Updated: 2026-05-01

...
...

A critical remote code execution vulnerability (CVE-2022-47939) was identified in the Linux kernel ksmbd in-kernel SMB server (introduced in 5.15), allowing potential kernel-level code execution via malformed SMB2_TREE_DISCONNECT handling; the issue scores highly (ZDI CVSS 10.0) but exposure is limited because ksmbd is rarely enabled by default and a patch was released in Linux 5.15.61.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.