CVE-2023-52440: Linux Kernel

High severity, CVSS 7.8. EPSS: 21.9% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix slub overflow in ksmbd_decode_ntlmssp_auth_blob() If authblob->SessionKey.Length is bigger than session key size(CIFS_KEY_SIZE), slub overflow can happen in key exchange codes. cifs_arc4_crypt copy to session key array from SessionKey from client.

Affected products

  • Linux Linux Kernel: from 5.17.0, before 6.1.52 (fixed in 6.1.52); from 6.2.0, before 6.4.15 (fixed in 6.4.15); from 6.5.0, before 6.5.2 (fixed in 6.5.2)

Published 2024-02-21. Last modified 2026-08-15.