CVE-2023-52440
Linux Debian vulnerability analysis and mitigation

Overview

CVE-2023-52440 is a vulnerability in the Linux kernel's ksmbd component, specifically in the ksmbd_decode_ntlmssp_auth_blob() function. The vulnerability was discovered in August 2023 and publicly disclosed in February 2024. It affects Linux kernel versions from 5.17.0 up to (excluding) 6.1.52, from 6.2.0 up to (excluding) 6.4.15, and from 6.5.0 up to (excluding) 6.5.2 (NVD).

Technical details

The vulnerability is a heap-based buffer overflow (CWE-119) that occurs when processing session keys in the ksmbd component. The issue arises when authblob->SessionKey.Length is larger than the session key size (CIFS_KEY_SIZE), causing a slub overflow during key exchange operations where cifs_arc4_crypt copies data to the session key array from the client's SessionKey. The vulnerability has been assigned a CVSS v3.1 base score of 7.8 (HIGH) with the vector string CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H (NVD, ZDI).

Impact

This vulnerability allows remote attackers to execute arbitrary code on affected installations of the Linux kernel. While authentication is not required to exploit this vulnerability, only systems with ksmbd enabled are vulnerable. The successful exploitation could lead to code execution in the context of the kernel, potentially resulting in complete system compromise with high impacts on confidentiality, integrity, and availability (ZDI).

Mitigation and workarounds

The vulnerability has been fixed in Linux kernel versions 6.1.52, 6.4.15, and 6.5.2. The fix involves adding a validation check to ensure that the session key length does not exceed CIFS_KEY_SIZE before performing the key exchange operations (Kernel Patch).

Additional resources


SourceThis report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-33230HIGH7.3
  • Linux DebianLinux Debian
  • nvidia-cuda-toolkit
NoNoJan 20, 2026
CVE-2025-33229HIGH7.3
  • Linux DebianLinux Debian
  • nvidia-cuda-toolkit
NoNoJan 20, 2026
CVE-2025-33228HIGH7.3
  • Linux DebianLinux Debian
  • nvidia-cuda-toolkit
NoNoJan 20, 2026
CVE-2025-33231MEDIUM6.7
  • Linux DebianLinux Debian
  • nvidia-cuda-toolkit
NoNoJan 20, 2026
CVE-2025-15281N/AN/A
  • WolfiWolfi
  • glibc-langpack-anp
NoYesJan 20, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management