CVE-2023-38426: Critical severity Linux Linux kernel vulnerability
An issue was discovered in the Linux kernel before 6.3.4. ksmbd has an out-of-bounds read in smb2findcontextvals when createcontext's namelen is larger than the tag length.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.25-1Fixed in 6.12.27-1 - Upgrade
Upgrade
Linux kernel (ksmbd)to a version that resolves this vulnerability.Fixed in 6.3.4 - Compensating control
If you cannot upgrade immediately, disable or restrict use/access to ksmbd (e.g., disable the KSMBD service) to reduce exposure to the smb2_find_context_vals out-of-bounds read.
Event History
Frequently Asked Questions
What is the severity of CVE-2023-38426?
CVE-2023-38426 has a high severity rating due to the out-of-bounds read vulnerability in the Linux kernel.
How do I fix CVE-2023-38426?
To fix CVE-2023-38426, upgrade your Linux kernel to version 6.3.4 or later.
Which versions of Linux are affected by CVE-2023-38426?
CVE-2023-38426 affects Linux kernel versions earlier than 6.3.4, including version 5.15.113 and those within the 5.16 to 6.1.30 range.
What software is impacted by CVE-2023-38426?
CVE-2023-38426 impacts the Linux kernel and specific NetApp solidfire and HCI management and storage nodes.
Is there a patch available for CVE-2023-38426?
Yes, there are patched versions available, including 5.10.223-1 and 6.12.12-1, among others.