{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2023-3866", "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "state": "PUBLISHED", "assignerShortName": "Linux", "dateReserved": "2023-07-24T14:52:41.881Z", "datePublished": "2025-08-16T13:27:57.332Z", "dateUpdated": "2026-08-05T09:09:48.015Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "shortName": "Linux", "dateUpdated": "2026-08-05T09:09:48.015Z" }, "descriptions": [ { "lang": "en", "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: validate session id and tree id in the compound request\n\nThis patch validate session id and tree id in compound request.\nIf first operation in the compound is SMB2 ECHO request, ksmbd bypass\nsession and tree validation. So work->sess and work->tcon could be NULL.\nIf secound request in the compound access work->sess or tcon, It cause\nNULL pointer dereferecing error." } ], "metrics": [ { "cvssV3_1": { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH" }, "scenarios": [ { "lang": "en", "value": "AV:N - The vulnerable code is in ksmbd (fs/smb/server/), the in-kernel SMB server reachable over TCP/445; a remote attacker triggers it by sending a crafted compound SMB2 request to a listening ksmbd instance.\nAC:L - The attacker fully controls the compound PDU layout and can reliably place SMB2_ECHO (or NEGOTIATE/SESSION_SETUP) first so session/tree validation is skipped for subsequent commands; no race or attacker-uncontrollable condition is required.\nPR:N - SMB2_ECHO/NEGOTIATE/SESSION_SETUP bypass smb2_check_user_session() without credentials, and with work->sess left NULL signing checks are also skipped, so the crash path is reachable pre-authentication over the network.\nUI:N - Exploitation requires only attacker-sent SMB2 compound packets to an already-running ksmbd listener; no victim user or administrator action is needed.\nS:U - Impact is confined to the host kernel/ksmbd security authority (kernel oops/DoS on the SMB server host); this is not a VM escape, IOMMU bypass, or other cross-authority boundary change.\nC:N - The defect is a pure NULL pointer dereference (e.g. tcon->share_conf with tcon NULL in smb2_open); it does not provide an information-disclosure or arbitrary-read primitive.\nI:N - The bug yields a NULL dereference crash rather than an out-of-bounds write, UAF, or other integrity/control-flow corruption primitive.\nA:H - Subsequent compound commands dereference NULL session/tree pointers, causing a kernel oops that an unauthenticated remote attacker can retrigger at will, denying service to ksmbd and potentially the host." } ] } ], "affected": [ { "product": "Linux", "vendor": "Linux", "defaultStatus": "unaffected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "fs/smb/server/server.c", "fs/smb/server/smb2pdu.c" ], "versions": [ { "version": "0626e6641f6b467447c81dd7678a69c66f7746cf", "lessThan": "eb947403518ea3d93f6d89264bb1f5416bb0c7d0", "status": "affected", "versionType": "git" }, { "version": "0626e6641f6b467447c81dd7678a69c66f7746cf", "lessThan": "854156d12caa9d36de1cf5f084591c7686cc8a9d", "status": "affected", "versionType": "git" }, { "version": "0626e6641f6b467447c81dd7678a69c66f7746cf", "lessThan": "d1066c1b3663401cd23c0d6e60cdae750ce00c0f", "status": "affected", "versionType": "git" }, { "version": "0626e6641f6b467447c81dd7678a69c66f7746cf", "lessThan": "5005bcb4219156f1bf7587b185080ec1da08518e", "status": "affected", "versionType": "git" } ] }, { "product": "Linux", "vendor": "Linux", "defaultStatus": "affected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "fs/smb/server/server.c", "fs/smb/server/smb2pdu.c" ], "versions": [ { "version": "5.15", "status": "affected" }, { "version": "0", "lessThan": "5.15", "status": "unaffected", "versionType": "semver" }, { "version": "5.15.121", "lessThanOrEqual": "5.15.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.1.36", "lessThanOrEqual": "6.1.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.3.10", "lessThanOrEqual": "6.3.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.4", "lessThanOrEqual": "*", "status": "unaffected", "versionType": "original_commit_for_fix" } ] } ], "cpeApplicability": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.15", "versionEndExcluding": "5.15.121" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.15", "versionEndExcluding": "6.1.36" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.15", "versionEndExcluding": "6.3.10" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.15", "versionEndExcluding": "6.4" } ] } ] } ], "references": [ { "url": "https://git.kernel.org/stable/c/eb947403518ea3d93f6d89264bb1f5416bb0c7d0" }, { "url": "https://git.kernel.org/stable/c/854156d12caa9d36de1cf5f084591c7686cc8a9d" }, { "url": "https://git.kernel.org/stable/c/d1066c1b3663401cd23c0d6e60cdae750ce00c0f" }, { "url": "https://git.kernel.org/stable/c/5005bcb4219156f1bf7587b185080ec1da08518e" } ], "title": "ksmbd: validate session id and tree id in the compound request", "x_generator": { "engine": "bippy-1.2.0" } } } }