Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Fri, 23 Dec 2022 00:41:11 -0800
From: Eric Biggers <ebiggers@...nel.org>
To: oss-security@...ts.openwall.com
Subject: Re: Details on this supposed Linux Kernel ksmbd RCE

On Fri, Dec 23, 2022 at 09:17:28AM +0100, Marcus Meissner wrote:
> Hi folks,
> 
> tldr: I requested 5 CVEs for the new ZDI issues Josh and Jan referenced.
> 
> long form:
> 
> Nice surprise 1 day before Christmas.

Note that these bugs were already fixed in upstream and all affected Long Term
Support (LTS) kernels months ago.  So this is really only a "surprise" for
people who choose to use known buggy and insecure kernels that don't follow LTS.

Anyway, these sorts of bugs are totally predictable in a complex, new network
filesystem server (ksmbd).  Personally I recommend not using ksmbd.

- Eric

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.