Buffer overflow in Linux kernel - CVE-2023-52434

 

Buffer overflow in Linux kernel - CVE-2023-52434

Published: April 9, 2024 / Updated: May 14, 2025


Vulnerability identifier: #VU88283
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2023-52434
CWE-ID: CWE-119
Exploitation vector: Adjecent network
Exploit availability: No public exploit available
Affected software:
Linux kernel
Debian Linux
Amazon Linux AMI
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise High Availability Extension 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for Power, little endian
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for Real Time for NFV
Red Hat Enterprise Linux for Real Time
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
SUSE Linux Enterprise Live Patching
Slackware Linux
Public Cloud Module
openSUSE Leap
Ubuntu
openEuler
IBM Integrated Analytics System
SmartFabric Storage Software
Juniper Secure Analytics (JSA)
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
linux-image-ibm (Ubuntu package)
linux-image-5.4.0-1077-ibm (Ubuntu package)
linux-image-5.4.0-1130-aws (Ubuntu package)
linux-image-5.4.0-1134-gcp (Ubuntu package)
linux-image-5.4.0-192-generic (Ubuntu package)
linux-image-5.4.0-192-lowlatency (Ubuntu package)
linux-image-oem (Ubuntu package)
linux-image-oem-osp1 (Ubuntu package)
linux-image-aws (Ubuntu package)
linux-image-gcp (Ubuntu package)
linux-image-generic-hwe-18.04 (Ubuntu package)
linux-image-lowlatency-hwe-18.04 (Ubuntu package)
linux-image-snapdragon-hwe-18.04 (Ubuntu package)
linux-image-virtual-hwe-18.04 (Ubuntu package)
linux-image-5.4.0-1129-oracle (Ubuntu package)
linux-image-oracle (Ubuntu package)
linux-image-5.4.0-1135-azure (Ubuntu package)
linux-image-azure (Ubuntu package)
linux-image-5.4.0-1114-raspi (Ubuntu package)
linux-image-raspi-hwe-18.04 (Ubuntu package)
kgraft-patch-4_12_14-122_244-default
gfs2-kmp-default-debuginfo
cluster-md-kmp-default
gfs2-kmp-default
ocfs2-kmp-default-debuginfo
dlm-kmp-default
dlm-kmp-default-debuginfo
ocfs2-kmp-default
cluster-md-kmp-default-debuginfo
kernel-default-devel
kernel-syms
kernel-default-base-debuginfo
kernel-default-kgraft-devel
kernel-default-base
kernel-default-kgraft
kernel-default-debugsource
kernel-macros
kernel-devel
kernel-source
kernel-default-man
kernel-default-debuginfo
kernel-default-devel-debuginfo
kernel-default
kernel (Red Hat package)
kernel-rt (Red Hat package)
kernel-cross-headers
kernel-doc
kernel-abi-stablelists
python3-perf
kernel
perf
bpftool
kernel-tools-libs-devel
kernel-tools-libs
kernel-tools
kernel-modules-extra
kernel-modules
kernel-headers
kernel-debug-modules-extra
kernel-debug-modules
kernel-debug-devel
kernel-debug-core
kernel-debug
kernel-core
linux-image-lowlatency (Ubuntu package)
linux-image-virtual (Ubuntu package)
linux-image-generic (Ubuntu package)
linux-image-generic-lpae (Ubuntu package)
linux-image-5.4.0-192-generic-lpae (Ubuntu package)
linux-image-5.4.0-1042-iot (Ubuntu package)
linux-image-xilinx-zynqmp (Ubuntu package)
linux-image-5.4.0-1049-xilinx-zynqmp (Ubuntu package)
linux-image-ibm-lts-20.04 (Ubuntu package)
linux-image-bluefield (Ubuntu package)
linux-image-5.4.0-1090-bluefield (Ubuntu package)
linux-image-gkeop-5.4 (Ubuntu package)
linux-image-gkeop (Ubuntu package)
linux-image-5.4.0-1097-gkeop (Ubuntu package)
linux-image-raspi2 (Ubuntu package)
linux-image-raspi (Ubuntu package)
linux-image-kvm (Ubuntu package)
linux-image-5.4.0-1118-kvm (Ubuntu package)
linux-image-oracle-lts-20.04 (Ubuntu package)
linux-image-aws-lts-20.04 (Ubuntu package)
linux-image-gcp-lts-20.04 (Ubuntu package)
linux-image-azure-lts-20.04 (Ubuntu package)
python3-perf-debuginfo
perf-debuginfo
kernel-tools-devel
kernel-tools-debuginfo
kernel-debuginfo
kernel-debugsource
bpftool-debuginfo
linux (Debian package)
linux-image-virtual-hwe-20.04 (Ubuntu package)
linux-image-5.15.0-113-generic-lpae (Ubuntu package)
linux-image-5.15.0-113-generic-64k (Ubuntu package)
linux-image-5.15.0-113-generic (Ubuntu package)
linux-image-generic-64k-hwe-20.04 (Ubuntu package)
linux-image-generic-hwe-20.04 (Ubuntu package)
linux-image-generic-lpae-hwe-20.04 (Ubuntu package)
linux-image-oem-20.04 (Ubuntu package)
linux-image-oem-20.04b (Ubuntu package)
linux-image-oem-20.04c (Ubuntu package)
linux-image-oem-20.04d (Ubuntu package)
linux-image-gkeop-5.15 (Ubuntu package)
linux-image-5.15.0-1046-gkeop (Ubuntu package)
linux-image-5.15.0-1057-ibm (Ubuntu package)
linux-image-raspi-nolpae (Ubuntu package)
linux-image-5.15.0-1058-raspi (Ubuntu package)
linux-image-5.15.0-1060-kvm (Ubuntu package)
linux-image-azure-lts-22.04 (Ubuntu package)
linux-image-5.15.0-1075-azure (Ubuntu package)
linux-image-5.15.0-1078-azure (Ubuntu package)
linux-image-azure-cvm (Ubuntu package)
linux-5.15.160/kernel-generic
linux-5.15.160/kernel-huge
linux-5.15.160/kernel-modules
linux-5.15.160/kernel-headers
kernel-syms-azure
kernel-azure-extra
reiserfs-kmp-azure
kselftests-kmp-azure-debuginfo
kernel-azure-extra-debuginfo
kernel-source-azure
kernel-devel-azure
kernel-azure-vdso
kernel-azure-vdso-debuginfo
kernel-azure
kernel-azure-optional-debuginfo
kselftests-kmp-azure
kernel-azure-devel
kernel-azure-debugsource
reiserfs-kmp-azure-debuginfo
ocfs2-kmp-azure
kernel-azure-livepatch-devel
cluster-md-kmp-azure
gfs2-kmp-azure-debuginfo
kernel-azure-devel-debuginfo
cluster-md-kmp-azure-debuginfo
gfs2-kmp-azure
ocfs2-kmp-azure-debuginfo
kernel-azure-optional
dlm-kmp-azure
dlm-kmp-azure-debuginfo
kernel-azure-debuginfo
linux-image-generic-64k (Ubuntu package)
linux-image-6.5.0-27-lowlatency (Ubuntu package)
linux-image-6.5.0-27-lowlatency-64k (Ubuntu package)
linux-image-lowlatency-hwe-22.04 (Ubuntu package)
linux-image-lowlatency-64k-hwe-22.04 (Ubuntu package)
linux-image-lowlatency-64k (Ubuntu package)
linux-image-6.5.0-27-generic (Ubuntu package)
linux-image-6.5.0-27-generic-64k (Ubuntu package)
linux-image-virtual-hwe-22.04 (Ubuntu package)
linux-image-generic-hwe-22.04 (Ubuntu package)
linux-image-generic-64k-hwe-22.04 (Ubuntu package)
linux-image-6.5.0-1011-starfive (Ubuntu package)
linux-image-starfive (Ubuntu package)
linux-image-6.5.0-1013-laptop (Ubuntu package)
linux-image-laptop-23.10 (Ubuntu package)
linux-image-6.5.0-1014-raspi (Ubuntu package)
linux-image-6.5.0-1017-aws (Ubuntu package)
linux-image-6.5.0-1017-gcp (Ubuntu package)
linux-image-6.5.0-1018-azure (Ubuntu package)
linux-image-6.5.0-1018-azure-fde (Ubuntu package)
linux-image-azure-fde (Ubuntu package)
linux-image-6.5.0-1019-oem (Ubuntu package)
linux-image-oem-22.04 (Ubuntu package)
linux-image-oem-22.04a (Ubuntu package)
linux-image-oem-22.04b (Ubuntu package)
linux-image-oem-22.04c (Ubuntu package)
linux-image-oem-22.04d (Ubuntu package)
linux-image-6.5.0-1020-oracle (Ubuntu package)
linux-image-6.5.0-1020-oracle-64k (Ubuntu package)
linux-image-oracle-64k (Ubuntu package)
Storage Copy Data Management
Technical Support Appliance
IBM Cloud Pak for Watson AIOps
Red Hat OpenShift Container Platform
IBM Qradar SIEM

Detailed vulnerability description

The vulnerability allows a remote user to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error within the smb2_parse_contexts() function when parsing SMB packets. A remote user can send specially crafted SMB traffic to the affected system, trigger memory corruption and execute arbitrary code.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


How to mitigate CVE-2023-52434

Install updates from vendor's website.

Sources