oss-sec mailing list archives

Re: Details on this supposed Linux Kernel ksmbd RCE


From: Eric Biggers <ebiggers () kernel org>
Date: Fri, 23 Dec 2022 00:41:11 -0800

On Fri, Dec 23, 2022 at 09:17:28AM +0100, Marcus Meissner wrote:
Hi folks,

tldr: I requested 5 CVEs for the new ZDI issues Josh and Jan referenced.

long form:

Nice surprise 1 day before Christmas.

Note that these bugs were already fixed in upstream and all affected Long Term
Support (LTS) kernels months ago.  So this is really only a "surprise" for
people who choose to use known buggy and insecure kernels that don't follow LTS.

Anyway, these sorts of bugs are totally predictable in a complex, new network
filesystem server (ksmbd).  Personally I recommend not using ksmbd.

- Eric


Current thread: