CVE-2023-38431: Linux Kernel
Critical severity, CVSS 9.1. EPSS: 1.2% chance of exploitation in the next 30 days.
An issue was discovered in the Linux kernel before 6.3.8. fs/smb/server/connection.c in ksmbd does not validate the relationship between the NetBIOS header's length field and the SMB header sizes, via pdu_size in ksmbd_conn_handler_loop, leading to an out-of-bounds read.
Affected products
- Linux Linux Kernel: from 5.15, before 5.15.145 (fixed in 5.15.145); from 5.16, before 6.1.34 (fixed in 6.1.34); from 6.2, before 6.3.8 (fixed in 6.3.8)
- Netapp h300s: affected versions not specified
- Netapp h410s: affected versions not specified
- Netapp h500s: affected versions not specified
- Netapp h700s: affected versions not specified
- Netapp Solidfire & Hci Management Node: affected versions not specified
Published 2023-07-18. Last modified 2026-06-17.