cbcvebase.
CVE-2023-6606
published 2023-12-08

CVE-2023-6606: An out-of-bounds read vulnerability was found in smbCalcSize in fs/smb/client/netmisc.c in the Linux Kernel. This issue could allow a local attacker to crash…

high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
An out-of-bounds read vulnerability was found in smbCalcSize in fs/smb/client/netmisc.c in the Linux Kernel. This issue could allow a local attacker to crash the system or leak internal kernel information.

Affected

20 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.76-1 (bookworm)linux 6.1.76-1 (bookworm)
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.209-15.10.209-1
linuxlinux_kernel>= 0 < 6.1.76-16.1.76-1
linuxlinux_kernel>= 0 < 6.6.9-16.6.9-1
linuxlinux_kernel>= 0 < 6.6.9-16.6.9-1
linuxlinux_kernel>= 0 < 5.4.0-170.1885.4.0-170.188
linuxlinux_kernel>= 0 < 5.15.0-92.1025.15.0-92.102
linuxlinux_kernel>= 0 < 4.4.0-250.2844.4.0-250.284
linuxlinux_kernel>= 0 < 4.15.0-221.2324.15.0-221.232
linuxlinux_kernel>= 6.4.1 < 6.76.7
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_linux_eus
redhatenterprise_linux_eus
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_for_power_little_endian_update_services_for_sap_solution
redhatenterprise_linux_server_for_power_little_endian_update_services_for_sap_solution

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv8.1HIGH