CVE-2023-38426: Linux Kernel

Critical severity, CVSS 9.1. EPSS: 3% chance of exploitation in the next 30 days.

An issue was discovered in the Linux kernel before 6.3.4. ksmbd has an out-of-bounds read in smb2_find_context_vals when create_context's name_len is larger than the tag length.

Affected products

  • Linux Linux Kernel: from 5.15, before 5.15.113 (fixed in 5.15.113); from 5.16, before 6.1.30 (fixed in 6.1.30); from 6.2, before 6.3.4 (fixed in 6.3.4)
  • Netapp h300s: affected versions not specified
  • Netapp h410s: affected versions not specified
  • Netapp h500s: affected versions not specified
  • Netapp h700s: affected versions not specified
  • Netapp Solidfire & Hci Management Node: affected versions not specified
  • Netapp Solidfire & Hci Storage Node: affected versions not specified

Published 2023-07-18. Last modified 2026-06-17.