5.5
CVE-2023-52442
- EPSS 0.25%
 - Published 21.02.2024 08:15:45
 - Last modified 01.10.2025 19:15:33
 - Source 416baaa9-dc9f-4396-8d5f-8c081f
 - CVE-Watchlists
 - Open
 
In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate session id and tree id in compound request `smb2_get_msg()` in smb2_get_ksmbd_tcon() and smb2_check_user_session() will always return the first request smb2 header in a compound request. if `SMB2_TREE_CONNECT_HE` is the first command in compound request, will return 0, i.e. The tree id check is skipped. This patch use ksmbd_req_buf_next() to get current command in compound.
Data is provided by the National Vulnerability Database (NVD)
	Linux ≫ Linux Kernel  Version >= 5.15 < 5.15.145
	Linux ≫ Linux Kernel  Version >= 5.16 < 6.1.53
	Linux ≫ Linux Kernel  Version >= 6.2 < 6.4.16
	Linux ≫ Linux Kernel Version6.5 Updaterc1 
	Linux ≫ Linux Kernel Version6.5 Updaterc2 
	Linux ≫ Linux Kernel Version6.5 Updaterc3 
| Type | Source | Score | Percentile | 
|---|---|---|---|
| EPSS | FIRST.org | 0.25% | 0.48 | 
| Source | Base Score | Exploit Score | Impact Score | Vector string | 
|---|---|---|---|---|
| nvd@nist.gov | 5.5 | 1.8 | 3.6 | 
                 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H  
             | 
        
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 5.5 | 1.8 | 3.6 | 
                 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H  
             |