Новости компьютерной безопасности:

  Latest News

Linux Kernel ksmbd Vulnerability Allows Remote Attackers to Execute Arbitrary Code

С сайта: Vulnerability(cybersecuritynews.com)

Linux Kernel ksmbd Vulnerability Allows Remote Attackers to Execute Arbitrary Code

Author: Florence Nightingale

A severe vulnerability in the Linux kernel’s ksmbd SMB server implementation has been disclosed, potentially allowing authenticated remote attackers to execute arbitrary code on affected systems. 

The vulnerability, tracked as CVE-2025-38561 and assigned a CVSS score of 8.5, represents a significant security risk for Linux systems utilizing the kernel-based SMB server functionality.

The flaw disclosed by the Zero Day initiative stems from improper handling of the Preauth_HashValue field within the smb2_sess_setup function.

This race condition vulnerability occurs due to inadequate locking mechanisms when performing operations on kernel objects, creating an opportunity for attackers to manipulate memory structures and achieve code execution within kernel context.

Linux Ksmbd Vulnerability (CVE-2025-38561)
The vulnerability specifically targets the ksmbd service, which provides in-kernel SMB server functionality as an alternative to the traditional Samba implementation. 

Unlike user-space SMB servers, ksmbd operates directly within the kernel space, making successful exploitation particularly dangerous as it grants attackers kernel-level privileges.

The attack requires initial authentication to the SMB service, meaning attackers must possess valid credentials or successfully authenticate through other means before triggering the vulnerability. 

Once authenticated, the race condition in the session setup process can be exploited to corrupt memory structures and redirect code execution flow.

Technical analysis reveals that the vulnerability manifests during SMB2 session establishment when the server processes authentication hash values.

The lack of proper synchronization between concurrent operations creates a window where memory corruption can occur, potentially leading to arbitrary code execution with kernel privileges.

The vulnerability disclosure follows responsible disclosure practices, with researcher Nicholas Zubrisky of Trend Research reporting the issue to Linux maintainers on July 22, 2025. 

Risk Factors Details Affected ProductsLinux Kernel (ksmbd SMB server implementation)ImpactRemote Code ExecutionExploit PrerequisitesAuthentication required – Valid SMB credentials needed to access ksmbd serviceCVSS 3.1 Score8.5 (High)
Mitigations
Linux maintainers have released patches addressing this vulnerability, with the fix available in the stable kernel tree under commit 44a3059c4c8cc635a1fb2afd692d0730ca1ba4b6. 

System administrators should prioritize updating their Linux kernels to versions containing this security fix, particularly on systems exposed to untrusted networks or users.

Organizations utilizing ksmbd for file-sharing services should implement additional security measures, including network segmentation, strict authentication controls, and monitoring for suspicious SMB traffic patterns.

Consider temporarily disabling ksmbd services on non-critical systems until patching can be completed.



#Cyber_Security_News #Vulnerability #Vulnerability_News #cyber_security #cyber_security_news #vulnerability

Оригинальная версия на сайте: Linux Kernel ksmbd Vulnerability Allows Remote Attackers to Execute Arbitrary Code
Вернуться к списку новостей К свежим новостям Здесь был google AdSense.
Вместо рекламы товаров началась политическая агитация.
Отключено до получения извинений.

Вернуться к списку новостей Здесь был google AdSense.
Вместо рекламы товаров началась политическая агитация.
Отключено до получения извинений.


Новости проекта CSN:

✉ CSN.net4me.net

Обновление сайта csn.net4me.net

Обновление сайта csn.net4me.net 💻
cyber security news
  • Физически мы переехали на новый сервер. Благодарим наших подписчиков и постоянных читателей за терпение и понимание.
  • Сайт csn.net4me.net полностью адаптирован для работы по шифрованному SSL соединению.
  • Изменен механизм обработки и отображения опасных и критических уязвимостей.

Благодарим что вы с нами.


#CSN_обновление_сайта
https://csn.net4me.net/cyber_security_8301.html

Дополнительный материал

О проекте CSN

Проект CSN.net4me.net родился 16 Марта 2018 года.
Проект находится в самом начале своего развития. Конечно оформление, наполнение будет меняться. Одно останется неизменным - самые свежие новости компьютерной и сетевой безопасности.

О проекте net4me

Проект net4me.net развивался как сборник готовых решений и документации по темам компьютерной безопасности, сетевых решений и СПО (в часности linux). Темпы развития IT отрасли оказались столь быстрыми, что некоторые знания, технологии и информация о них устаревали мгновенно. Тем не менее, некоторый материал net4me.net до сих пор востребован.

Об источниках

Новости берутся CSN из открытых и доступных каждому источников. Авторы проекта стараются подбирать авторитетные и проверенные источники. Но, тем не менее, не несут ответственности за содержимое новостей. В каждой новости указывается источник этой новости, её автор и ссылка на оригинал новости.

Информация

Если вы желаете чтобы новости вашего ресурса были размещены на сайте CSN, то свяжитесь с авторами проекта csn@net4me.net и предложите ссылку на rss или xml ленту новостей вашего ресурса. Любая предложенная информация будет рассмотрена редакцией.