LiveActive security incident?Get immediate response
CVE Record

CVE-2023-54203: ksmbd: fix slab-out-of-bounds in init_smb2_rsp_hdr

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix slab-out-of-bounds in init_smb2_rsp_hdr When smb1 mount fails, KASAN detect slab-out-of-bounds in init_smb2_rsp_hdr like the following one. For smb1 negotiate(56bytes) , init_smb2_rsp_hdr() for smb2 is called. The issue occurs while handling smb1 negotiate as smb2 server operations. Add smb server operations for smb1 (get_cmd_val, init_rsp_hdr, allocate_rsp_buf, check_user_session) to handle smb1 negotiate so that smb2 server operation does not handle it. [ 411.400423] CIFS: VFS: Use of the less secure dialect vers=1.0 is not recommended unless required for access to very old servers [ 411.400452] CIFS: Attempting to mount \\192.168.45.139\homes [ 411.479312] ksmbd: init_smb2_rsp_hdr : 492 [ 411.479323] ================================================================== [ 411.479327] BUG: KASAN: slab-out-of-bounds in init_smb2_rsp_hdr+0x1e2/0x1f4 [ksmbd] [ 411.479369] Read of size 16 at addr ffff888488ed0734 by task kworker/14:1/199 [ 411.479379] CPU: 14 PID: 199 Comm: kworker/14:1 Tainted: G OE 6.1.21 #3 [ 411.479386] Hardware name: ASUSTeK COMPUTER INC. Z10PA-D8 Series/Z10PA-D8 Series, BIOS 3801 08/23/2019 [ 411.479390] Workqueue: ksmbd-io handle_ksmbd_work [ksmbd] [ 411.479425] Call Trace: [ 411.479428] <TASK> [ 411.479432] dump_stack_lvl+0x49/0x63 [ 411.479444] print_report+0x171/0x4a8 [ 411.479452] ? kasan_complete_mode_report_info+0x3c/0x200 [ 411.479463] ? init_smb2_rsp_hdr+0x1e2/0x1f4 [ksmbd] [ 411.479497] kasan_report+0xb4/0x130 [ 411.479503] ? init_smb2_rsp_hdr+0x1e2/0x1f4 [ksmbd] [ 411.479537] kasan_check_range+0x149/0x1e0 [ 411.479543] memcpy+0x24/0x70 [ 411.479550] init_smb2_rsp_hdr+0x1e2/0x1f4 [ksmbd] [ 411.479585] handle_ksmbd_work+0x109/0x760 [ksmbd] [ 411.479616] ? _raw_spin_unlock_irqrestore+0x50/0x50 [ 411.479624] ? smb3_encrypt_resp+0x340/0x340 [ksmbd] [ 411.479656] process_one_work+0x49c/0x790 [ 411.479667] worker_thread+0x2b1/0x6e0 [ 411.479674] ? process_one_work+0x790/0x790 [ 411.479680] kthread+0x177/0x1b0 [ 411.479686] ? kthread_complete_and_exit+0x30/0x30 [ 411.479692] ret_from_fork+0x22/0x30 [ 411.479702] </TASK>

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysisunknown

Security readout for executives and security teams

Plain-English summary

CVE-2023-54203 is a Linux kernel ksmbd bug where failed SMB1 negotiation can be handled by SMB2 response logic, causing an out-of-bounds slab read detected by KASAN. Business risk is mainly for systems running the in-kernel SMB server where legacy SMB1 traffic can reach the service.

Executive priority

Treat as a targeted kernel SMB hardening item. Prioritize internet-exposed or broadly reachable ksmbd systems, but urgency is constrained by missing CVSS, no KEV listing, and no cited exploitation evidence.

Technical view

In ksmbd, SMB1 negotiate failure could reach init_smb2_rsp_hdr(), causing a 16-byte slab out-of-bounds read. The fix adds SMB1-specific server operations for command value handling, response header initialization, response buffer allocation, and session checking so SMB2 handlers do not process SMB1 negotiate traffic.

Likely exposure

Exposure appears limited to Linux systems using ksmbd, the kernel SMB server, particularly where SMB1 negotiation attempts can reach it. The provided record does not establish broader product impact.

Exploitation context

The source shows a KASAN crash report during an SMB1 mount attempt. It does not cite active exploitation, public exploit availability, or weaponized use. KEV is false.

Researcher notes

The record identifies a memory-safety bug in ksmbd response initialization when SMB1 negotiate traffic is misrouted to SMB2 operations. The affected-version data is sparse, so validate against distribution advisories and the referenced stable commits.

Mitigation direction

  • Check vendor kernel guidance for CVE-2023-54203 and apply applicable stable updates.
  • Prioritize systems running ksmbd and reachable over SMB ports.
  • Disable or restrict legacy SMB1 access where operationally possible.
  • Limit network reachability to trusted clients using firewall or segmentation controls.

Validation and detection

  • Inventory Linux hosts running ksmbd or exposing SMB services.
  • Compare kernel versions and downstream patches against vendor advisories.
  • Review logs for ksmbd errors around SMB1 negotiation failures.
  • Confirm SMB exposure is limited to intended networks and clients.
Prepared
Confidence
medium
Sources
6

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2023-54203 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
3Timeline events
0ADP providers
5Source links

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. CVE publishedCVE Program

    The CVE record was published.

  3. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
LinuxLinux51a8534c0f35c0401e45f1055f914729cad98bf9, 0b3ec5671ac06829ccebdaeec05acedfec327f42, cc32cd98a0aee4cc3eb611cbce11795b1aaa738a, 39b291b86b5988bf8753c3874d5c773399d09b96unaffected
LinuxLinux5.15.105, 6.1.22, 6.2.9unaffected
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.