CVE-2023-52442

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
21/02/2024
Last modified:
12/12/2024

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> ksmbd: validate session id and tree id in compound request<br /> <br /> `smb2_get_msg()` in smb2_get_ksmbd_tcon() and smb2_check_user_session()<br /> will always return the first request smb2 header in a compound request.<br /> if `SMB2_TREE_CONNECT_HE` is the first command in compound request, will<br /> return 0, i.e. The tree id check is skipped.<br /> This patch use ksmbd_req_buf_next() to get current command in compound.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.15 (including) 5.15.145 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.16 (including) 6.1.53 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.2 (including) 6.4.16 (excluding)
cpe:2.3:o:linux:linux_kernel:6.5:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.5:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.5:rc3:*:*:*:*:*:*