CVE-2023-38432: Linux Kernel

Critical severity, CVSS 9.1. EPSS: 2.5% chance of exploitation in the next 30 days.

An issue was discovered in the Linux kernel before 6.3.10. fs/smb/server/smb2misc.c in ksmbd does not validate the relationship between the command payload size and the RFC1002 length specification, leading to an out-of-bounds read.

Affected products

  • Linux Linux Kernel: from 5.15, before 5.15.121 (fixed in 5.15.121); from 5.16, before 6.1.36 (fixed in 6.1.36); from 6.2, before 6.3.10 (fixed in 6.3.10)
  • Netapp h300s: affected versions not specified
  • Netapp h410s: affected versions not specified
  • Netapp h500s: affected versions not specified
  • Netapp h700s: affected versions not specified
  • Netapp Solidfire: affected versions not specified
  • Netapp Solidfire & Hci Storage Node: affected versions not specified

Published 2023-07-18. Last modified 2026-06-17.