CVE-2023-38427: Linux Kernel

Critical severity, CVSS 9.8. EPSS: 1.2% chance of exploitation in the next 30 days.

An issue was discovered in the Linux kernel before 6.3.8. fs/smb/server/smb2pdu.c in ksmbd has an integer underflow and out-of-bounds read in deassemble_neg_contexts.

Affected products

  • Linux Linux Kernel: from 5.15, before 5.15.145 (fixed in 5.15.145); from 5.16, before 6.1.34 (fixed in 6.1.34); from 6.2, before 6.3.8 (fixed in 6.3.8)
  • Netapp h300s: affected versions not specified
  • Netapp h410s: affected versions not specified
  • Netapp h500s: affected versions not specified
  • Netapp h700s: affected versions not specified

Published 2023-07-18. Last modified 2026-06-17.