A vulnerability has been identified in the Linux kernel's ksmbd component (kernel SMB/CIFS server). A security control designed to prevent dictionary attacks, which introduces a 5-second delay during session setup, can be bypassed through the use of asynchronous requests. This bypass negates the intended anti-brute-force protection, potentially allowing attackers to conduct dictionary attacks more efficiently against user credentials or other authentication mechanisms.
History

Fri, 01 Aug 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 01 Aug 2025 01:30:00 +0000


Thu, 31 Jul 2025 21:00:00 +0000

Type Values Removed Values Added
Description A vulnerability has been identified in the Linux kernel's ksmbd component (kernel SMB/CIFS server). A security control designed to prevent dictionary attacks, which introduces a 5-second delay during session setup, can be bypassed through the use of asynchronous requests. This bypass negates the intended anti-brute-force protection, potentially allowing attackers to conduct dictionary attacks more efficiently against user credentials or other authentication mechanisms.
Title Kernel: ksmbd brute force delay bypass via asynchronous requests
First Time appeared Redhat
Redhat enterprise Linux
Weaknesses CWE-307
CPEs cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2025-07-31T20:44:02.968Z

Updated: 2025-08-01T13:29:57.568Z

Reserved: 2023-05-05T10:00:07.895Z

Link: CVE-2023-32251

cve-icon Vulnrichment

Updated: 2025-08-01T13:29:47.528Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-07-31T21:15:26.810

Modified: 2025-08-04T15:06:36.623

Link: CVE-2023-32251

cve-icon Redhat

No data.