{"id":"CVE-2023-32251","title":"A vulnerability has been identified in the Linux kernel's ksmbd component (kernel SMB/CIFS server)","summary":"A vulnerability has been identified in the Linux kernel's ksmbd component (kernel SMB/CIFS server). A security control designed to prevent dictionary attacks, which introduces a 5-second delay during session setup, can be bypassed throug…","severity":"low","cvss":3.7,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","cwe":["CWE-307"],"published":"2025-07-31","updated":"2026-06-25","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2023-32251","references":[{"url":"https://access.redhat.com/security/cve/CVE-2023-32251","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2385852","label":"secalert@redhat.com"},{"url":"https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=b096d97f47326b1e2dbdef1c91fab69ffda54d17","label":"secalert@redhat.com"},{"url":"https://www.zerodayinitiative.com/advisories/ZDI-23-699/","label":"secalert@redhat.com"}],"tags":["nvd"],"epss":0.00442,"epssPercentile":0.37834,"zeroDay":true,"ingestedAt":"2026-06-29T13:24:34.402Z","slug":"CVE-2023-32251","body":"## Overview\n\nA vulnerability has been identified in the Linux kernel's ksmbd component (kernel SMB/CIFS server). A security control designed to prevent dictionary attacks, which introduces a 5-second delay during session setup, can be bypassed through the use of asynchronous requests. This bypass negates the intended anti-brute-force protection, potentially allowing attackers to conduct dictionary attacks more efficiently against user credentials or other authentication mechanisms.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":45,"depthScoreParts":{"impact":20.4,"likelihood":0.1,"exploitation":25,"ransomware":0},"changes":[]}