CVE-2023-52441

Source
https://cve.org/CVERecord?id=CVE-2023-52441
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-52441.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2023-52441
Downstream
Published
2024-02-21T07:21:01.075Z
Modified
2026-04-11T12:46:30.291915Z
Summary
ksmbd: fix out of bounds in init_smb2_rsp_hdr()
Details

In the Linux kernel, the following vulnerability has been resolved:

ksmbd: fix out of bounds in initsmb2rsp_hdr()

If client send smb2 negotiate request and then send smb1 negotiate request, initsmb2rsphdr is called for smb1 negotiate request since needneg is set to false. This patch ignore smb1 packets after ->need_neg is set to false.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/52xxx/CVE-2023-52441.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
0626e6641f6b467447c81dd7678a69c66f7746cf
Fixed
5c0df9d30c289d6b9d7d44e2a450de2f8e3cf40b
Fixed
330d900620dfc9893011d725b3620cd2ee0bc2bc
Fixed
aa669ef229ae8dd779da9caa24e254964545895f
Fixed
536bb492d39bb6c080c92f31e8a55fe9934f452b

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-52441.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.15.0
Fixed
5.15.145
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.53
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.4.16

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-52441.json"