Vulnerability record · CVE-2023-0210 · published 27 March 2023
CVE-2023-0210: Linux kernel ksmbd NTLMv2 heap overflow causes remote crash
Linux · Linux Kernel
The Linux kernel's ksmbd SMB server has a heap-based buffer overflow and out-of-bounds write in its NTLMv2 authentication handling. A remote, unauthenticated attacker can trigger the bug and crash the operating system immediately, making it a denial-of-service issue for systems exposing ksmbd.
Description
A bug affects the Linux kernel’s ksmbd NTLMv2 authentication and is known to crash the OS immediately in Linux-based systems.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Automated analysis
high priorityUnauthenticated remote kernel crash with a very high EPSS score and public exploit references, though not listed in CISA KEV.
What it is
The Linux kernel's ksmbd SMB server has a heap-based buffer overflow and out-of-bounds write in its NTLMv2 authentication handling. A remote, unauthenticated attacker can trigger the bug and crash the operating system immediately, making it a denial-of-service issue for systems exposing ksmbd.
Impact
An attacker gains the ability to crash the kernel, taking down the affected Linux system and any services it hosts. The record describes only availability impact; no code execution or data disclosure is stated.
Attack surface
Reachable over the network via the ksmbd SMB service, as reflected by the CVSS vector AV:N/PR:N/UI:N. No authentication or user interaction is required to reach the vulnerable NTLMv2 authentication path.
Exploitation
CISA KEV does not list this CVE, but EPSS is very high (0.71737, 99.393rd percentile) and multiple references are tagged Exploit, indicating public exploit material exists.
What to do
- Apply the upstream Linux kernel patches referenced in the git.kernel.org and cifsd-team commits, or update to a kernel release containing the fix.
- If ksmbd is not required, disable or do not load the ksmbd module to remove the attack surface.
- Restrict network access to SMB/ksmbd ports (445/139) to trusted hosts using firewall or security group rules.
- Monitor vendor advisories such as the NetApp advisory for affected product updates.
- Where patching is delayed, consider running ksmbd in a constrained environment or replacing it with an alternative SMB implementation.
Detection
- Monitor ksmbd/SMB service logs and system logs for kernel crashes, oops messages, or unexpected reboots on hosts running ksmbd.
- Alert on unexpected ksmbd process termination or kernel panic events correlated with inbound SMB traffic.
- Track network connections to SMB ports from untrusted or unusual sources, especially repeated authentication attempts.
- Use host-based monitoring to detect kernel crash dumps or watchdog resets on Linux systems exposing ksmbd.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2023-0210 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-0210), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.