CVE-2023-54250
ksmbd: avoid out of bounds access in decode_preauth_ctxt()
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
In the Linux kernel, the following vulnerability has been resolved: ksmbd: avoid out of bounds access in decode_preauth_ctxt() Confirm that the accessed pneg_ctxt->HashAlgorithms address sits within the SMB request boundary; deassemble_neg_contexts() only checks that the eight byte smb2_neg_context header + (client controlled) DataLength are within the packet boundary, which is insufficient. Checking for sizeof(struct smb2_preauth_neg_context) is overkill given that the type currently assumes SMB311_SALT_SIZE bytes of trailing Salt.
| Vendor | linux |
| Product | linux |
| Ecosystems | |
| Industries | Technology |
| Published | Dec 30, 2025 |
| Last Updated | May 11, 2026 |
Stay Ahead of the Next One
Get instant alerts for linux linux
Be the first to know when new unknown vulnerabilities affecting linux linux are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Linux / Linux
e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 < 39f5b4b313b445c980a2a295bed28228c29228ed e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 < a2f6ded41bec1d3be643c80a5eb97f1680309001 e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 < f02edb9debbd36f44efa7567031485892c7df60d e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 < e7067a446264a7514fa1cfaa4052cdb6803bc6a2
Linux / Linux
5.15
References
git.kernel.org: https://git.kernel.org/stable/c/39f5b4b313b445c980a2a295bed28228c29228ed git.kernel.org: https://git.kernel.org/stable/c/a2f6ded41bec1d3be643c80a5eb97f1680309001 git.kernel.org: https://git.kernel.org/stable/c/f02edb9debbd36f44efa7567031485892c7df60d git.kernel.org: https://git.kernel.org/stable/c/e7067a446264a7514fa1cfaa4052cdb6803bc6a2