Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-52440
HistoryFeb 21, 2024 - 12:00 a.m.

CVE-2023-52440

2024-02-2100:00:00
ubuntu.com
ubuntu.com
13
linux kernel
vulnerability
ksmbd
slub overflow
ntlmssp
auth blob
key exchange code

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

6.9

Confidence

High

EPSS

0

Percentile

15.9%

In the Linux kernel, the following vulnerability has been resolved: ksmbd:
fix slub overflow in ksmbd_decode_ntlmssp_auth_blob() If
authblob->SessionKey.Length is bigger than session key size(CIFS_KEY_SIZE),
slub overflow can happen in key exchange codes. cifs_arc4_crypt copy to
session key array from SessionKey from client.

Bugs

Notes

Author Note
sbeattie ZDI-CAN-21940
OSVersionArchitecturePackageVersionFilename
ubuntu22.04noarchlinux-oem-6.5< 6.5.0-1004.4UNKNOWN

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

6.9

Confidence

High

EPSS

0

Percentile

15.9%