CVE-2023-32249
A critical flaw in the Linux kernel's SMB server (ksmbd) could allow a guest user to be accepted on multichannel connections, leading to high confidentiality and integrity impacts. The vulnerability has a CVSS base score of 9.1. A patch has been released that prevents guest user binding on multichannel by returning STATUS_NOT_SUPPORTED.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Linux kernel users
Real-world impact
An attacker could exploit this to gain unauthorized access to sensitive data or modify data on affected systems.
Why this severity
CVSS 9.1 (Critical) reflects the network‑adjacent, low‑complexity attack that requires no privileges or user interaction and can compromise confidentiality and integrity.
What to do about it
- 01Apply the Linux kernel patch that resolves CVE-2023-32249 (the ksmbd guest user multichannel fix).
NVD description indicating the vulnerability has been resolved
Timeline
- Aug 16, 2025 · Aug 16, 2025PublishedDisclosed and added to the National Vulnerability Database.
- Aug 4, 2026 · 1d agoAdvisory updatedThe NVD record was last revised.
- Aug 4, 2026 · 1d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.