ksmbd: fix out of bounds in init_smb2_rsp_hdr()

Summary

CVECVE-2023-52441
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2024-02-21 08:15:45 UTC
Updated2026-08-15 13:17:41 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: ksmbd: fix out of bounds in init_smb2_rsp_hdr() If client send smb2 negotiate request and then send smb1 negotiate request, init_smb2_rsp_hdr is called for smb1 negotiate request since need_neg is set to false. This patch ignore smb1 packets after ->need_neg is set to false.

Risk And Classification

Primary CVSS: v3.1 7.8 HIGH from [email protected]

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Problem Types: CWE-119


VersionSourceTypeScoreSeverityVector
3.1[email protected]Primary7.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
3.1416baaa9-dc9f-4396-8d5f-8c081fb06d67Secondary9.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
3.1CNADECLARED9.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

CVSS v3.1 Breakdown

Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

NVD Known Affected Configurations (CPE 2.3)

TypeVendorProductVersionUpdateEditionLanguage
Operating System Linux Linux Kernel All All All All

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected 51a8534c0f35c0401e45f1055f914729cad98bf9 5c0df9d30c289d6b9d7d44e2a450de2f8e3cf40b git Not specified
CNA Linux Linux affected 0b3ec5671ac06829ccebdaeec05acedfec327f42 330d900620dfc9893011d725b3620cd2ee0bc2bc git Not specified
CNA Linux Linux affected 39b291b86b5988bf8753c3874d5c773399d09b96 aa669ef229ae8dd779da9caa24e254964545895f git Not specified
CNA Linux Linux affected 39b291b86b5988bf8753c3874d5c773399d09b96 536bb492d39bb6c080c92f31e8a55fe9934f452b git Not specified
CNA Linux Linux affected cc32cd98a0aee4cc3eb611cbce11795b1aaa738a git Not specified
CNA Linux Linux affected 5.15.105 5.15.145 semver Not specified
CNA Linux Linux affected 6.1.22 6.1.53 semver Not specified
CNA Linux Linux affected 6.2.9 6.3 semver Not specified
CNA Linux Linux affected 6.3 Not specified
CNA Linux Linux unaffected 6.3 semver Not specified
CNA Linux Linux unaffected 5.15.145 5.15.* semver Not specified
CNA Linux Linux unaffected 6.1.53 6.1.* semver Not specified
CNA Linux Linux unaffected 6.4.16 6.4.* semver Not specified
CNA Linux Linux unaffected 6.5 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/536bb492d39bb6c080c92f31e8a55fe9934f452b af854a3a-2127-422b-91ae-364da2661108 git.kernel.org Patch
git.kernel.org/stable/c/aa669ef229ae8dd779da9caa24e254964545895f af854a3a-2127-422b-91ae-364da2661108 git.kernel.org Patch
git.kernel.org/stable/c/330d900620dfc9893011d725b3620cd2ee0bc2bc af854a3a-2127-422b-91ae-364da2661108 git.kernel.org Patch
git.kernel.org/stable/c/5c0df9d30c289d6b9d7d44e2a450de2f8e3cf40b af854a3a-2127-422b-91ae-364da2661108 git.kernel.org Patch
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

Legacy QID Mappings

  • 200243 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6725-1)

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report