CVE-2023-38426Out-of-bounds Read in Kernel

CWE-125Out-of-bounds Read22 documents7 sources
Severity
9.1CRITICALNVD
OSV7.8
EPSS
0.1%
top 78.05%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 18
Latest updateSep 18

Description

An issue was discovered in the Linux kernel before 6.3.4. ksmbd has an out-of-bounds read in smb2_find_context_vals when create_context's name_len is larger than the tag length.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:HExploitability: 3.9 | Impact: 5.2

Affected Packages3 packages

NVDlinux/linux_kernel5.155.15.113+2
Debianlinux/linux_kernel< 6.1.37-1+2
Ubuntulinux/linux_kernel< 5.15.0-83.92

Patches

🔴Vulnerability Details

11
OSV
linux-intel-iotg vulnerabilities2023-09-18
OSV
linux-azure, linux-azure-5.15, linux-azure-fde, linux-azure-fde-5.15, linux-raspi vulnerabilities2023-09-11
OSV
linux-gcp, linux-gcp-6.2, linux-ibm, linux-oracle, linux-starfive vulnerabilities2023-09-08
OSV
linux-gcp-5.15, linux-gkeop-5.15 vulnerabilities2023-09-08
OSV
linux-gke, linux-gkeop vulnerabilities2023-09-06

📋Vendor Advisories

10
Ubuntu
Linux kernel (Intel IoTG) vulnerabilities2023-09-18
Ubuntu
Linux kernel vulnerabilities2023-09-11
Ubuntu
Linux kernel vulnerabilities2023-09-08
Ubuntu
Linux kernel vulnerabilities2023-09-08
Ubuntu
Linux kernel (Azure) vulnerabilities2023-09-06