CVE-2023-38429

Updated: 2025-08-20 00:20:19.4813

Description:

An issue was discovered in the Linux kernel before 6.3.4. fs/ksmbd/connection.c in ksmbd has an off-by-one error in memory allocation (because of ksmbd_smb2_check_message) that may lead to out-of-bounds access.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0.0
CVSS Version 3.x CRITICAL 9.8

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU kernel 5.14.0 9.8 CRITICAL Not Vulnerable 2024-04-18 11:13:59
CentOS 6 ELS kernel 2.6.32 9.8 CRITICAL Not Vulnerable 2023-08-26 00:55:49
CentOS 7 ELS kernel 3.10.0 9.8 CRITICAL Not Vulnerable 2023-11-04 09:33:40
CentOS 8.4 ELS kernel 4.18.0 9.8 CRITICAL Not Vulnerable 2023-08-26 00:55:49
CentOS 8.5 ELS kernel 4.18.0 9.8 CRITICAL Not Vulnerable 2023-08-26 04:00:23
CloudLinux 6 ELS kernel 2.6.32 9.8 CRITICAL Not Vulnerable 2023-08-26 00:55:49
Oracle Linux 6 ELS kernel 2.6.32 9.8 CRITICAL Not Vulnerable 2023-08-26 00:55:49
Ubuntu 16.04 ELS linux-hwe 4.15.0 9.8 CRITICAL Not Vulnerable 2023-08-15 09:14:38
Ubuntu 16.04 ELS linux 4.4.0 9.8 CRITICAL Not Vulnerable 2023-08-15 09:14:37
Ubuntu 18.04 ELS linux 4.15.0 9.8 CRITICAL Not Vulnerable 2023-08-26 00:55:52