boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Thursday, August 20, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2023-32249

Linux Linux — ksmbd: not allow guest user on multichannel
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   L   L   L   N  U  N  N  H    5.5   .0034   26.9     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    f5a544e3bab78142207e0242d22442db85ba1eff –  —
  Linux    5.15 –                                      5.15.112
TIMELINE
  May 5   Reserved by Linux
  Aug 16  Published (CNA: Linux)
  Aug 15  RESCORED — CVE-2023-32249 (Linux). CVSS 9.1 → 5.5 (NVD).
CNA: Linux · CVSS v3.1 · 5 references · NVD status: Modified

Description

In the Linux kernel, the following vulnerability has been resolved: ksmbd: not allow guest user on multichannel This patch return STATUS_NOT_SUPPORTED if binding session is guest.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
May 5, 2023ReservedReserved by Linux
August 16, 2025PublishedPublished (CNA: Linux)
August 15, 2026RESCOREDRESCORED — CVE-2023-32249 (Linux). CVSS 9.1 → 5.5 (NVD).

Affected

Affected products and packages — 2 rows
VendorProduct / PackageEcosystemVersion introducedFixed
LinuxLinuxf5a544e3bab78142207e0242d22442db85ba1eff
LinuxLinux5.155.15.112

References (5)

Related

Authoritative record: CVE-2023-32249 at cve.org

Vendors: linux

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2023-32249 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Thursday, August 20, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.