PT-2023-8716 · Linux+3 · Linux Kernel+3
Published
2023-08-29
·
Updated
2025-10-04
·
Published
2023-08-29
·
Updated
2025-10-04
·
10
High
| Base vector | Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
ksmbd decode ntlmssp auth blob() function. This issue relates to a heap-based buffer overflow that can occur during session key exchange. The problem arises when the SessionKey.Length within the authblob structure exceeds the expected CIFS KEY SIZE. This can lead to a slub overflow during key exchange operations, as the cifs arc4 crypt function copies data from the client's SessionKey into a session key array without proper size validation. Successful exploitation of this issue could allow a remote attacker to execute arbitrary code.Exploit
Fix
Buffer Overflow
Integer Overflow