cbcvebase.
CVE-2023-4515
published 2025-08-16

CVE-2023-4515: In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate command request size In commit 2b9b8f3b68ed ("ksmbd: validate command…

PriorityP424medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.29%
21.5th percentile
In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate command request size In commit 2b9b8f3b68ed ("ksmbd: validate command payload size"), except for SMB2_OPLOCK_BREAK_HE command, the request size of other commands is not checked, it's not expected. Fix it by add check for request size of other commands.

Affected

23 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.52-1 (bookworm)linux 6.1.52-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux>= 2b9b8f3b68edb3d67d79962f02e26dbb5ae3808d < ff7236b66d69582f90cf5616e63cfc3dc18142bbff7236b66d69582f90cf5616e63cfc3dc18142bb
linuxlinux>= 2b9b8f3b68edb3d67d79962f02e26dbb5ae3808d < 5aa4fda5aa9c2a5a7bac67b4a12b089ab81fee3c5aa4fda5aa9c2a5a7bac67b4a12b089ab81fee3c
linuxlinux>= 35f450f54dca1519bb24faacd0428db09f89a11f < 595679098bdcdbfbba91ebe07a2f7f208df93870595679098bdcdbfbba91ebe07a2f7f208df93870
linuxlinux>= 5.15.121 < 5.15.1275.15.127
linuxlinux>= 6.1.36 < 6.1.466.1.46
linuxlinux>= 6.3.10 < 6.46.4
linuxlinux>= 9650cf70ec9d94ff34daa088b643229231723c26 < c6bef3bc30fd4a175aef846b7d928a6c40d091cdc6bef3bc30fd4a175aef846b7d928a6c40d091cd
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.52-16.1.52-1
linuxlinux_kernel>= 0 < 6.4.11-16.4.11-1
linuxlinux_kernel>= 0 < 6.4.11-16.4.11-1
linuxlinux_kernel>= 5.15.121 < 5.15.1275.15.127
linuxlinux_kernel>= 6.1.36 < 6.1.466.1.46
linuxlinux_kernel>= 6.3.10 < 6.46.4
linuxlinux_kernel>= 6.4.1 < 6.4.116.4.11

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.