CVE-2023-38428: Critical severity Linux Linux kernel vulnerability
An issue was discovered in the Linux kernel before 6.3.4. fs/ksmbd/smb2pdu.c in ksmbd does not properly check the UserName value because it does not consider the address of security buffer, leading to an out-of-bounds read.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.25-1 - Upgrade
Upgrade
Linux kernelto a version that resolves this vulnerability.Fixed in 6.3.4
Event History
Frequently Asked Questions
What is the severity of CVE-2023-38428?
CVE-2023-38428 is considered a high severity vulnerability due to its potential for causing out-of-bounds reads in the Linux kernel.
How do I fix CVE-2023-38428?
To fix CVE-2023-38428, update your Linux kernel to a version later than 6.3.4 or to one of the specified patched versions like 5.10.223-1 or 6.1.123-1.
Which systems are affected by CVE-2023-38428?
CVE-2023-38428 affects various versions of the Linux kernel prior to 6.3.4 and certain NetApp SolidFire and HCI management nodes.
What is the nature of the vulnerability in CVE-2023-38428?
CVE-2023-38428 involves inadequate checks of the UserName value leading to an out-of-bounds read, which could be exploited for information disclosure.
When was CVE-2023-38428 last updated?
CVE-2023-38428 was last updated on November 29, 2024.