CVE-2023-54203
Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
30/12/2025
Última modificación:
30/12/2025
Descripción
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
ksmbd: fix slab-out-of-bounds in init_smb2_rsp_hdr<br />
<br />
When smb1 mount fails, KASAN detect slab-out-of-bounds in<br />
init_smb2_rsp_hdr like the following one.<br />
For smb1 negotiate(56bytes) , init_smb2_rsp_hdr() for smb2 is called.<br />
The issue occurs while handling smb1 negotiate as smb2 server operations.<br />
Add smb server operations for smb1 (get_cmd_val, init_rsp_hdr,<br />
allocate_rsp_buf, check_user_session) to handle smb1 negotiate so that<br />
smb2 server operation does not handle it.<br />
<br />
[ 411.400423] CIFS: VFS: Use of the less secure dialect vers=1.0 is<br />
not recommended unless required for access to very old servers<br />
[ 411.400452] CIFS: Attempting to mount \\192.168.45.139\homes<br />
[ 411.479312] ksmbd: init_smb2_rsp_hdr : 492<br />
[ 411.479323] ==================================================================<br />
[ 411.479327] BUG: KASAN: slab-out-of-bounds in<br />
init_smb2_rsp_hdr+0x1e2/0x1f4 [ksmbd]<br />
[ 411.479369] Read of size 16 at addr ffff888488ed0734 by task kworker/14:1/199<br />
<br />
[ 411.479379] CPU: 14 PID: 199 Comm: kworker/14:1 Tainted: G<br />
OE 6.1.21 #3<br />
[ 411.479386] Hardware name: ASUSTeK COMPUTER INC. Z10PA-D8<br />
Series/Z10PA-D8 Series, BIOS 3801 08/23/2019<br />
[ 411.479390] Workqueue: ksmbd-io handle_ksmbd_work [ksmbd]<br />
[ 411.479425] Call Trace:<br />
[ 411.479428] <br />
[ 411.479432] dump_stack_lvl+0x49/0x63<br />
[ 411.479444] print_report+0x171/0x4a8<br />
[ 411.479452] ? kasan_complete_mode_report_info+0x3c/0x200<br />
[ 411.479463] ? init_smb2_rsp_hdr+0x1e2/0x1f4 [ksmbd]<br />
[ 411.479497] kasan_report+0xb4/0x130<br />
[ 411.479503] ? init_smb2_rsp_hdr+0x1e2/0x1f4 [ksmbd]<br />
[ 411.479537] kasan_check_range+0x149/0x1e0<br />
[ 411.479543] memcpy+0x24/0x70<br />
[ 411.479550] init_smb2_rsp_hdr+0x1e2/0x1f4 [ksmbd]<br />
[ 411.479585] handle_ksmbd_work+0x109/0x760 [ksmbd]<br />
[ 411.479616] ? _raw_spin_unlock_irqrestore+0x50/0x50<br />
[ 411.479624] ? smb3_encrypt_resp+0x340/0x340 [ksmbd]<br />
[ 411.479656] process_one_work+0x49c/0x790<br />
[ 411.479667] worker_thread+0x2b1/0x6e0<br />
[ 411.479674] ? process_one_work+0x790/0x790<br />
[ 411.479680] kthread+0x177/0x1b0<br />
[ 411.479686] ? kthread_complete_and_exit+0x30/0x30<br />
[ 411.479692] ret_from_fork+0x22/0x30<br />
[ 411.479702]



