CVE-2023-54203: ksmbd: fix slab-out-of-bounds in init_smb2_rsp_hdr
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: fix slab-out-of-bounds in init_smb2_rsp_hdr
When smb1 mount fails, KASAN detect slab-out-of-bounds in
init_smb2_rsp_hdr like the following one.
For smb1 negotiate(56bytes) , init_smb2_rsp_hdr() for smb2 is called.
The issue occurs while handling smb1 negotiate as smb2 server operations.
Add smb server operations for smb1 (get_cmd_val, init_rsp_hdr,
allocate_rsp_buf, check_user_session) to handle smb1 negotiate so that
smb2 server operation does not handle it.
[ 411.400423] CIFS: VFS: Use of the less secure dialect vers=1.0 is
not recommended unless required for access to very old servers
[ 411.400452] CIFS: Attempting to mount \\192.168.45.139\homes
[ 411.479312] ksmbd: init_smb2_rsp_hdr : 492
[ 411.479323] ==================================================================
[ 411.479327] BUG: KASAN: slab-out-of-bounds in
init_smb2_rsp_hdr+0x1e2/0x1f4 [ksmbd]
[ 411.479369] Read of size 16 at addr ffff888488ed0734 by task kworker/14:1/199
[ 411.479379] CPU: 14 PID: 199 Comm: kworker/14:1 Tainted: G
OE 6.1.21 #3
[ 411.479386] Hardware name: ASUSTeK COMPUTER INC. Z10PA-D8
Series/Z10PA-D8 Series, BIOS 3801 08/23/2019
[ 411.479390] Workqueue: ksmbd-io handle_ksmbd_work [ksmbd]
[ 411.479425] Call Trace:
[ 411.479428] <TASK>
[ 411.479432] dump_stack_lvl+0x49/0x63
[ 411.479444] print_report+0x171/0x4a8
[ 411.479452] ? kasan_complete_mode_report_info+0x3c/0x200
[ 411.479463] ? init_smb2_rsp_hdr+0x1e2/0x1f4 [ksmbd]
[ 411.479497] kasan_report+0xb4/0x130
[ 411.479503] ? init_smb2_rsp_hdr+0x1e2/0x1f4 [ksmbd]
[ 411.479537] kasan_check_range+0x149/0x1e0
[ 411.479543] memcpy+0x24/0x70
[ 411.479550] init_smb2_rsp_hdr+0x1e2/0x1f4 [ksmbd]
[ 411.479585] handle_ksmbd_work+0x109/0x760 [ksmbd]
[ 411.479616] ? _raw_spin_unlock_irqrestore+0x50/0x50
[ 411.479624] ? smb3_encrypt_resp+0x340/0x340 [ksmbd]
[ 411.479656] process_one_work+0x49c/0x790
[ 411.479667] worker_thread+0x2b1/0x6e0
[ 411.479674] ? process_one_work+0x790/0x790
[ 411.479680] kthread+0x177/0x1b0
[ 411.479686] ? kthread_complete_and_exit+0x30/0x30
[ 411.479692] ret_from_fork+0x22/0x30
[ 411.479702] </TASK>
Security readout for executives and security teams
Plain-English summary
CVE-2023-54203 is a Linux kernel ksmbd bug where failed SMB1 negotiation can be handled by SMB2 response logic, causing an out-of-bounds slab read detected by KASAN. Business risk is mainly for systems running the in-kernel SMB server where legacy SMB1 traffic can reach the service.
Executive priority
Treat as a targeted kernel SMB hardening item. Prioritize internet-exposed or broadly reachable ksmbd systems, but urgency is constrained by missing CVSS, no KEV listing, and no cited exploitation evidence.
Technical view
In ksmbd, SMB1 negotiate failure could reach init_smb2_rsp_hdr(), causing a 16-byte slab out-of-bounds read. The fix adds SMB1-specific server operations for command value handling, response header initialization, response buffer allocation, and session checking so SMB2 handlers do not process SMB1 negotiate traffic.
Likely exposure
Exposure appears limited to Linux systems using ksmbd, the kernel SMB server, particularly where SMB1 negotiation attempts can reach it. The provided record does not establish broader product impact.
Exploitation context
The source shows a KASAN crash report during an SMB1 mount attempt. It does not cite active exploitation, public exploit availability, or weaponized use. KEV is false.
Researcher notes
The record identifies a memory-safety bug in ksmbd response initialization when SMB1 negotiate traffic is misrouted to SMB2 operations. The affected-version data is sparse, so validate against distribution advisories and the referenced stable commits.
Mitigation direction
Check vendor kernel guidance for CVE-2023-54203 and apply applicable stable updates.
Prioritize systems running ksmbd and reachable over SMB ports.
Disable or restrict legacy SMB1 access where operationally possible.
Limit network reachability to trusted clients using firewall or segmentation controls.
Validation and detection
Inventory Linux hosts running ksmbd or exposing SMB services.
Compare kernel versions and downstream patches against vendor advisories.
Review logs for ksmbd errors around SMB1 negotiation failures.
Confirm SMB exposure is limited to intended networks and clients.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cve · low confidence lookup
CVE-2023-54203 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
0CVSS vectors
3Timeline events
0ADP providers
5Source links
Vulnerability timeline
Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.
CVE reservedCVE Program
The CVE ID was reserved by the assigning CNA.
CVE publishedCVE Program
The CVE record was published.
Dec 30, 2025, 12:09 UTC (UTC+00:00)
CVE updatedCVE Program
The CVE record metadata indicates this as the latest update time.