Junglewise Threat Intelligence

CVE-2023-54250: Linux kernel ksmbd out of bounds access in decode_preauth_ctxt

CVE-2023-54250 · Severity: high · CVSS 8.2 · Published 2025-12-30

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

ksmbd is a Linux kernel SMB/CIFS server implementation that handles network file-sharing protocols. An out-of-bounds memory read in the preauth context handling allows unauthenticated remote attackers to read sensitive kernel memory, potentially exposing cryptographic keys or other confidential data, and could lead to kernel crashes or information disclosure.

Technical details

The vulnerability is an out-of-bounds memory access (CWE-125) in the decode_preauth_ctxt() function within fs/ksmbd/smb2pdu.c. The deassemble_neg_contexts() function validates only that the 8-byte SMB2 negotiation context header plus the client-controlled DataLength field fit within the SMB request packet boundary, but does not sufficiently validate the actual payload structure. When processing SMB3.1.1 preauth integrity contexts, the code accesses pneg_ctxt->HashAlgorithms without confirming adequate remaining buffer space, allowing a remote attacker to craft a malicious SMB request with insufficient payload to trigger an out-of-bounds read. No authentication is required; the vulnerability is reachable over the network. An attacker can read kernel memory adjacent to the context structure or cause a kernel panic (denial of service). A patch adds proper length validation requiring at least 6 bytes of context data before accessing HashAlgorithms.

Affected products

  • Linux Linux kernel multiple stable branches (5.4, 5.10, 5.15, 6.1 and others) prior to fix commit e7067a44

Timeline

  • 2023-12-19: disclosed: Patch authored
  • 2023-12-23: patched: Fix committed upstream (commit e7067a44) and backported to stable branches
  • 2025-12-30: advisory

References

Related threats