PT-2023-8703 · Linux+4 · Linux Kernel+4

Publicado

2023-07-23

·

Atualizado

2025-10-01

·

CVE-2023-52442

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux Kernel (affected versions not specified)
Description The issue is related to the improper validation of session id and tree id in compound requests in the Linux kernel's ksmbd module. Specifically, the smb2 get msg() function in smb2 get ksmbd tcon() and smb2 check user session() always returns the first request smb2 header in a compound request. If SMB2 TREE CONNECT HE is the first command in a compound request, it returns 0, effectively skipping the tree id check. This can be exploited by a remote attacker to potentially elevate privileges. The vulnerability is related to the ksmbd req buf next() function used to get the current command in a compound request.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Out of bounds Read

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2024-01629
CVE-2023-52442
USN-6725-1
USN-6725-2
ZDI-24-227

Produtos afetados

Astra Linux
Linux Kernel
Linuxmint
Red Os
Ubuntu