CVE-2023-1194: Fedoraproject Fedora

High severity, CVSS 8.1. EPSS: 1.1% chance of exploitation in the next 30 days.

An out-of-bounds (OOB) memory read flaw was found in parse_lease_state in the KSMBD implementation of the in-kernel samba server and CIFS in the Linux kernel. When an attacker sends the CREATE command with a malformed payload to KSMBD, due to a missing check of `NameOffset` in the `parse_lease_state()` function, the `create_context` object can access invalid memory.

Affected products

  • Fedoraproject Fedora: version 37 only
  • Linux Linux Kernel: from 5.15, before 5.15.145 (fixed in 5.15.145); from 5.16, before 6.1.34 (fixed in 6.1.34); from 6.2, before 6.3.8 (fixed in 6.3.8); version 6.4 only

Published 2023-11-03. Last modified 2026-06-17.