Rewterz penetration testing services help organizations determine if a cyber attacker can gain access to their critical assets while giving them detailed insights of the overall business impact of a cyber attack.
Before Rewterz got its start, the market was in dire need of a specialized and dedicated information security company. It was nearly impossible for businesses to find a trustworthy provider that could truly cover all of their bases. We wanted to meet this need, giving companies across the globe a chance to get ahead while knowing that their data is in good hands.
Rewterz penetration testing services help organizations determine if a cyber attacker can gain access to their critical assets while giving them detailed insights of the overall business impact of a cyber attack.
Before Rewterz got its start, the market was in dire need of a specialized and dedicated information security company. It was nearly impossible for businesses to find a trustworthy provider that could truly cover all of their bases. We wanted to meet this need, giving companies across the globe a chance to get ahead while knowing that their data is in good hands.
High
CVE-2023-32257 CVSS:8.1
Linux Kernel could allow a remote attacker to execute arbitrary code on the system, caused by a race condition in the processing of SMB2_SESSION_SETUP and SMB2_LOGOFF commands By sending a specially crafted request, an attacker could exploit this vulnerability to execute arbitrary code in the context of the kernel.
CVE-2023-32256 CVSS:7.5
Linux Kernel could allow a remote attacker to obtain sensitive information, caused by a race condition during the processing of SMB2_QUERY_INFO and SMB2_LOGOFF commands. By sending a specially crafted HTTP request, an attacker could exploit this vulnerability to obtain sensitive information or cause a denial of service condition.
CVE-2023-32255 CVSS:5.3
Linux Kernel is vulnerable to a denial of service, caused by memory leak in the handling of SMB2_SESSION_SETUP commands. By sending a specially crafted request, a remote attacker could exploit this vulnerability to cause a denial of service condition.
CVE-2023-32254 CVSS:9.8
Linux Kernel could allow a remote attacker to execute arbitrary code on the system, caused by a race condition in the processing of SMB2_TREE_DISCONNECT commands. By sending a specially crafted request, an attacker could exploit this vulnerability to execute arbitrary code in the context of the kernel.
Linux
Refer to Linux Kernel GIT Repository for patch, upgrade or suggested workaround information.