CVE-2023-38429: Linux Kernel

Critical severity, CVSS 9.8. EPSS: 1.2% chance of exploitation in the next 30 days.

An issue was discovered in the Linux kernel before 6.3.4. fs/ksmbd/connection.c in ksmbd has an off-by-one error in memory allocation (because of ksmbd_smb2_check_message) that may lead to out-of-bounds access.

Affected products

  • Linux Linux Kernel: from 5.15, before 5.15.113 (fixed in 5.15.113); from 5.16, before 6.1.30 (fixed in 6.1.30); from 6.2, before 6.3.4 (fixed in 6.3.4)

Published 2023-07-18. Last modified 2026-06-17.