VYPR
Critical severity9.8NVD Advisory· Published Feb 21, 2024· Updated Aug 15, 2026

CVE-2023-52440

CVE-2023-52440

Description

In the Linux kernel, the following vulnerability has been resolved:

ksmbd: fix slub overflow in ksmbd_decode_ntlmssp_auth_blob()

If authblob->SessionKey.Length is bigger than session key size(CIFS_KEY_SIZE), slub overflow can happen in key exchange codes. cifs_arc4_crypt copy to session key array from SessionKey from client.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • Linux/Kernel3 versions
    cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*range: >=5.17.0,<6.1.52
    • (no CPE)
    • (no CPE)range: 5.15
  • osv-coords
    Range: >= 5.17.0, < 6.1.52

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.