CVE-2023-52755: Linux Kernel

Critical severity, CVSS 9.8. EPSS: 28.1% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix slab out of bounds write in smb_inherit_dacl() slab out-of-bounds write is caused by that offsets is bigger than pntsd allocation size. This patch add the check to validate 3 offsets using allocation size.

Affected products

  • Linux Linux Kernel: from 5.15, before 5.15.140 (fixed in 5.15.140); from 5.16, before 6.1.64 (fixed in 6.1.64); from 6.2, before 6.5.13 (fixed in 6.5.13); from 6.6, before 6.6.3 (fixed in 6.6.3)

Published 2024-05-21. Last modified 2026-08-04.