#ksmbd

ꙮ liilliil 🇫🇯🇱🇨🇱🇧liilliil@mastodon.online
2025-06-02

Ебучие бляди, захуй вы убили в #ksmbd поддержку #smb1 (#cifs)?

История: раньше работало всё через самбу, обновил #openwrt, они там отказались от «устаревших» протоколов. Маки отвалились, виндовоз (нахуй нужен) работает. Пришлось поставить кошерный #afp через #netatalk
Аминь

2024-12-14

#ksmbd なんてのがあるのか #Linux

Joxean Koret (@matalaz)joxean
2023-09-17

Let's briefly talk about : Why? I mean, as a vulnerability researcher, that sounds like fun. As a defender, it sounds like not fun at all.

2023-09-10

phoronix.com/news/KSMBD-Stable
Finally, I can enjoy all of my classic Windows SMB vulnerabilities on Linux, thanks to KSMBD. This will truly be the Year of the Linux Desktop. Nothing can possibli go wrong. /s
#linux #smb #ksmbd #yearofthelinuxdesktop #nothingcanpossibligowrong

Smol Bean [OLD] (moved to https://evil.social/@shrimple)chocolatefossty@im-in.space
2023-09-09

I'm excited for #Linux 6.6, there are a lot of small goodies added/fixed and I just found out about #KSMBD which got me excited to try out.

2023-05-27

#kSMBd: a quick overview

“At the end of 2021, an LWN article caught our attention. A new SMB server implementation was being actively developed and on top of that, it was an in-kernel Linux implementation. Thus, our spring break was booked.”

blog.thalium.re/posts/ksmbd-tr

crackerjack :fedora: :donor:crackerjack@infosec.exchange
2023-01-26

Glad most distros aren't enabling ksmbd by default! Another RCE has been discovered. Great breakdown of detection and mitigating here.

#cybersecuritynews #rce #KSMBD

sysdig.com/blog/cve-2023-0210-

Critical Linux Vulnerability: Jack Wallen says the flaw has been found to affect SMB servers and can lead to remote code execution fosslife.org/critical-linux-vu #Linux #vulnerability #SMB #networking #security #KSMBD #SMB3 #FileSharing

sphere filled with the word "SECURITY" connected to multiple computers
2022-12-30

"리눅스 커널에서 발견된 초고위험도 취약점, SMB 서버 위협"

SMB3 프로토콜을 커널 내에 구현한 ksmbd에서 초고위험도 취약점 발견. ksmbd는 리눅스 커널 5.15에서 처음 도입. 대부분은 사용자들은 ksmbd가 아니라 삼바를 사용하기에 취약점의 영향이 광범위하지는 않음.

boannews.com/media/view.asp?id

Scripter :verified_flashing:scripter@social.tchncs.de
2022-12-28

Ksmbd: Kritische Lücke im SMB-Dienst des Linux-Kernels - Golem.de
glm.io/170747?n #Linux #LinuxKernel #KSMBD #Sicherheitslücke

Ksmbd: Kritische Lücke im SMB-Dienst des Linux-Kernels - Golem.de
golem.de/news/ksmbd-kritische-

"Bei der nun veröffentlichten Lücke handelt es sich um einen Use-After-Free-Fehler, der offenbar automatisiert gefunden wurde."

Klingt nach einem sehr trivialen Bug. Schade, dass das Entwicklerteam den nicht selbst gefunden hat

#smb #ksmbd #rce

2022-12-22

Regarding the latest KSMBD / #Linux Kernel CVSS 10.0 vulnerability:

How often are organizations using #KSMBD (SMB in the kernel?) and how many linux servers are typically using SMB in general?

zerodayinitiative.com/advisori

I understand it’s an impactful bug that can lead to RCE - but I’ve not seen KSMBD enabled on any of the linux servers that I have access to.

Dr. David McBride (dwm)dwm
2022-12-22

CVSS 10.0 RCE in Linux kernel ksmbd component:

zerodayinitiative.com/advisori

Appears to have been patched in 5.15.61 in August, so anyone keeping up with upstream security patches ought to be okay?

Fix in upstream commit cf6531d98190fa2cf92a6d8bbc8af0a4740a223c

No CVE appears to as yet have been assigned. (Which is somewhat upsetting given this bug was spotted and fixed 6 months ago!)

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst