smb: client: fix potential OOBs in smb2_parse_contexts()

Summary

CVECVE-2023-52434
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2024-02-20 18:15:50 UTC
Updated2026-08-04 10:18:26 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential OOBs in smb2_parse_contexts() Validate offsets and lengths before dereferencing create contexts in smb2_parse_contexts(). This fixes following oops when accessing invalid create contexts from server: BUG: unable to handle page fault for address: ffff8881178d8cc3 #PF: supervisor read access in kernel mode #PF: error_code(0x0000) - not-present page PGD 4a01067 P4D 4a01067 PUD 0 Oops: 0000 [#1] PREEMPT SMP NOPTI CPU: 3 PID: 1736 Comm: mount.cifs Not tainted 6.7.0-rc4 #1 Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.16.2-3-gd478f380-rebuilt.opensuse.org 04/01/2014 RIP: 0010:smb2_parse_contexts+0xa0/0x3a0 [cifs] Code: f8 10 75 13 48 b8 93 ad 25 50 9c b4 11 e7 49 39 06 0f 84 d2 00 00 00 8b 45 00 85 c0 74 61 41 29 c5 48 01 c5 41 83 fd 0f 76 55 <0f> b7 7d 04 0f b7 45 06 4c 8d 74 3d 00 66 83 f8 04 75 bc ba 04 00 RSP: 0018:ffffc900007939e0 EFLAGS: 00010216 RAX: ffffc90000793c78 RBX: ffff8880180cc000 RCX: ffffc90000793c90 RDX: ffffc90000793cc0 RSI: ffff8880178d8cc0 RDI: ffff8880180cc000 RBP: ffff8881178d8cbf R08: ffffc90000793c22 R09: 0000000000000000 R10: ffff8880180cc000 R11: 0000000000000024 R12: 0000000000000000 R13: 0000000000000020 R14: 0000000000000000 R15: ffffc90000793c22 FS: 00007f873753cbc0(0000) GS:ffff88806bc00000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: ffff8881178d8cc3 CR3: 00000000181ca000 CR4: 0000000000750ef0 PKRU: 55555554 Call Trace: <TASK> ? __die+0x23/0x70 ? page_fault_oops+0x181/0x480 ? search_module_extables+0x19/0x60 ? srso_alias_return_thunk+0x5/0xfbef5 ? exc_page_fault+0x1b6/0x1c0 ? asm_exc_page_fault+0x26/0x30 ? smb2_parse_contexts+0xa0/0x3a0 [cifs] SMB2_open+0x38d/0x5f0 [cifs] ? smb2_is_path_accessible+0x138/0x260 [cifs] smb2_is_path_accessible+0x138/0x260 [cifs] cifs_is_path_remote+0x8d/0x230 [cifs] cifs_mount+0x7e/0x350 [cifs] cifs_smb3_do_mount+0x128/0x780 [cifs] smb3_get_tree+0xd9/0x290 [cifs] vfs_get_tree+0x2c/0x100 ? capable+0x37/0x70 path_mount+0x2d7/0xb80 ? srso_alias_return_thunk+0x5/0xfbef5 ? _raw_spin_unlock_irqrestore+0x44/0x60 __x64_sys_mount+0x11a/0x150 do_syscall_64+0x47/0xf0 entry_SYSCALL_64_after_hwframe+0x6f/0x77 RIP: 0033:0x7f8737657b1e

Risk And Classification

Primary CVSS: v3.1 8 HIGH from [email protected]

CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Problem Types: CWE-119


VersionSourceTypeScoreSeverityVector
3.1[email protected]Primary8HIGHCVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
3.1416baaa9-dc9f-4396-8d5f-8c081fb06d67Secondary8.1HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
3.1CNADECLARED8.1HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H

CVSS v3.1 Breakdown

Attack Vector
Adjacent
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

NVD Known Affected Configurations (CPE 2.3)

TypeVendorProductVersionUpdateEditionLanguage
Operating System Linux Linux Kernel All All All All

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected b8c32dbb0deb287a5fcb78251e4eae6c7275760d 6726429c18c62dbf5e96ebbd522f262e016553fb git Not specified
CNA Linux Linux affected b8c32dbb0deb287a5fcb78251e4eae6c7275760d 13fb0fc4917621f3dfa285a27eaf7151d770b5e5 git Not specified
CNA Linux Linux affected b8c32dbb0deb287a5fcb78251e4eae6c7275760d 890bc4fac3c0973a49cac35f634579bebba7fe48 git Not specified
CNA Linux Linux affected b8c32dbb0deb287a5fcb78251e4eae6c7275760d 1ae3c59355dc9882e09c020afe8ffbd895ad0f29 git Not specified
CNA Linux Linux affected b8c32dbb0deb287a5fcb78251e4eae6c7275760d 17a0f64cc02d4972e21c733d9f21d1c512963afa git Not specified
CNA Linux Linux affected b8c32dbb0deb287a5fcb78251e4eae6c7275760d af1689a9b7701d9907dfc84d2a4b57c4bc907144 git Not specified
CNA Linux Linux affected 3.7 Not specified
CNA Linux Linux unaffected 3.7 semver Not specified
CNA Linux Linux unaffected 5.4.277 5.4.* semver Not specified
CNA Linux Linux unaffected 5.10.211 5.10.* semver Not specified
CNA Linux Linux unaffected 5.15.150 5.15.* semver Not specified
CNA Linux Linux unaffected 6.1.79 6.1.* semver Not specified
CNA Linux Linux unaffected 6.6.8 6.6.* semver Not specified
CNA Linux Linux unaffected 6.7 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/13fb0fc4917621f3dfa285a27eaf7151d770b5e5 af854a3a-2127-422b-91ae-364da2661108 git.kernel.org Patch
security.netapp.com/advisory/ntap-20250117-0009 af854a3a-2127-422b-91ae-364da2661108 security.netapp.com
git.kernel.org/stable/c/af1689a9b7701d9907dfc84d2a4b57c4bc907144 af854a3a-2127-422b-91ae-364da2661108 git.kernel.org Patch
lists.debian.org/debian-lts-announce/2024/06/msg00017.html af854a3a-2127-422b-91ae-364da2661108 lists.debian.org Mailing List
git.kernel.org/stable/c/17a0f64cc02d4972e21c733d9f21d1c512963afa af854a3a-2127-422b-91ae-364da2661108 git.kernel.org Patch
git.kernel.org/stable/c/1ae3c59355dc9882e09c020afe8ffbd895ad0f29 af854a3a-2127-422b-91ae-364da2661108 git.kernel.org Patch
git.kernel.org/stable/c/890bc4fac3c0973a49cac35f634579bebba7fe48 af854a3a-2127-422b-91ae-364da2661108 git.kernel.org Patch
git.kernel.org/stable/c/6726429c18c62dbf5e96ebbd522f262e016553fb af854a3a-2127-422b-91ae-364da2661108 git.kernel.org Patch
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

Legacy QID Mappings

  • 200242 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6724-1)
  • 357301 Amazon Linux Security Advisory for kernel : ALAS2023-2024-549
  • 357358 Amazon Linux Security Advisory for kernel : ALAS2KERNEL-5.10-2024-052
  • 357366 Amazon Linux Security Advisory for kernel : ALAS2KERNEL-5.15-2024-040
  • 6000567 Debian Security Update for linux (DSA 5658-1)
  • 6140436 AWS Bottlerocket Security Update for kernel (GHSA-gr44-rgmj-qv2r)
  • 6140451 AWS Bottlerocket Security Update for kernel (GHSA-fjq8-vw34-5p9f)

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report