cbcvebase.
CVE-2023-3865
published 2025-08-16

CVE-2023-3865: In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix out-of-bound read in smb2_write ksmbd_smb2_check_message doesn't validate…

PriorityP430high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.36%
29.2th percentile
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix out-of-bound read in smb2_write ksmbd_smb2_check_message doesn't validate hdr->NextCommand. If ->NextCommand is bigger than Offset + Length of smb2 write, It will allow oversized smb2 write length. It will cause OOB read in smb2_write.

Affected

15 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.37-1 (bookworm)linux 6.1.37-1 (bookworm)
linuxlinux
linuxlinux>= 0626e6641f6b467447c81dd7678a69c66f7746cf < 3813eee5154d6a4c5875cb4444cb2b63bac8947f3813eee5154d6a4c5875cb4444cb2b63bac8947f
linuxlinux>= 0626e6641f6b467447c81dd7678a69c66f7746cf < c86211159bc3178b891e0d60e586a32c7b6a231bc86211159bc3178b891e0d60e586a32c7b6a231b
linuxlinux>= 0626e6641f6b467447c81dd7678a69c66f7746cf < 58a9c41064df27632e780c5a3ae3e0e4284957d158a9c41064df27632e780c5a3ae3e0e4284957d1
linuxlinux>= 0626e6641f6b467447c81dd7678a69c66f7746cf < 5fe7f7b78290638806211046a99f031ff26164e15fe7f7b78290638806211046a99f031ff26164e1
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.37-16.1.37-1
linuxlinux_kernel>= 0 < 6.3.11-16.3.11-1
linuxlinux_kernel>= 0 < 6.3.11-16.3.11-1
linuxlinux_kernel>= 0 < 5.15.0-86.965.15.0-86.96
linuxlinux_kernel>= 5.15 < 5.15.1215.15.121
linuxlinux_kernel>= 5.16 < 6.1.366.1.36
linuxlinux_kernel>= 6.2 < 6.3.106.3.10
ubuntulinux-intel-iotg-5.15

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv9.8CRITICAL
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
vendor_ubuntu7.0HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.