cbcvebase.
CVE-2023-52441
published 2024-02-21

CVE-2023-52441: In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix out of bounds in init_smb2_rsp_hdr() If client send smb2 negotiate request and…

PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.38%
30.5th percentile
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix out of bounds in init_smb2_rsp_hdr() If client send smb2 negotiate request and then send smb1 negotiate request, init_smb2_rsp_hdr is called for smb1 negotiate request since need_neg is set to false. This patch ignore smb1 packets after ->need_neg is set to false.

Affected

13 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.55-1 (bookworm)linux 6.1.55-1 (bookworm)
linuxlinux
linuxlinux>= 0626e6641f6b467447c81dd7678a69c66f7746cf < 5c0df9d30c289d6b9d7d44e2a450de2f8e3cf40b5c0df9d30c289d6b9d7d44e2a450de2f8e3cf40b
linuxlinux>= 0626e6641f6b467447c81dd7678a69c66f7746cf < 330d900620dfc9893011d725b3620cd2ee0bc2bc330d900620dfc9893011d725b3620cd2ee0bc2bc
linuxlinux>= 0626e6641f6b467447c81dd7678a69c66f7746cf < aa669ef229ae8dd779da9caa24e254964545895faa669ef229ae8dd779da9caa24e254964545895f
linuxlinux>= 0626e6641f6b467447c81dd7678a69c66f7746cf < 536bb492d39bb6c080c92f31e8a55fe9934f452b536bb492d39bb6c080c92f31e8a55fe9934f452b
linuxlinux_kernel>= 0 < 6.1.55-16.1.55-1
linuxlinux_kernel>= 0 < 6.5.3-16.5.3-1
linuxlinux_kernel>= 0 < 6.5.3-16.5.3-1
linuxlinux_kernel>= 0 < 5.15.0-102.1125.15.0-102.112
linuxlinux_kernel>= 5.15.0 < 5.15.1455.15.145
linuxlinux_kernel>= 5.16.0 < 6.1.536.1.53
linuxlinux_kernel>= 6.2.0 < 6.4.166.4.16

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.1HIGH
vendor_debian7.8HIGH
vendor_ubuntu7.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.