CVE-2023-26607: High severity linux kernel vulnerability
Published Feb 26, 2023
·Updated
In the Linux kernel 6.0.8, there is an out-of-bounds read in ntfsattrfind in fs/ntfs/attrib.c.
Affected Software
13 affected componentsFixes available
Linux Linux kernel>=2.6.12<4.9.334
Linux Linux kernel>=4.10<4.14.300
Linux Linux kernel>=4.15<4.19.267
Linux Linux kernel>=4.20<5.4.225
Linux Linux kernel>=5.5.0<5.10.156
Linux Linux kernel>=5.11<5.15.80
Linux Linux kernel>=5.16<6.0.10
NetApp Hci Baseboard Management Controller=h300s
NetApp Hci Baseboard Management Controller=h410c
NetApp Hci Baseboard Management Controller=h410s
NetApp Hci Baseboard Management Controller=h500s
NetApp Hci Baseboard Management Controller=h700s
debian/linux
5.10.223-15.10.234-16.1.129-16.1.135-16.12.25-1
Remediation
Event History
Feb 26, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeaknessAffected Software
Mar 28, 2024
Data Sourced
via Launchpad·12:49 AM
Description
Apr 28, 2025
Data Sourced
via Ubuntu·02:10 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-26607?
CVE-2023-26607 has a critical severity level due to its potential for out-of-bounds read in the Linux kernel.
2
How do I fix CVE-2023-26607?
To fix CVE-2023-26607, update your Linux kernel to versions 5.10.223-1, 6.1.123-1, or later.
3
Which Linux kernel versions are affected by CVE-2023-26607?
CVE-2023-26607 affects Linux kernel versions between 2.6.12 and 6.0.10.
4
What components are impacted by CVE-2023-26607?
CVE-2023-26607 impacts the NTFS file system's attribute handling within the Linux kernel.
5
Is my system at risk with CVE-2023-26607?
If your system is running an affected version of the Linux kernel, it may be vulnerable to CVE-2023-26607.