First published: Mon Jul 17 2023(Updated: )
An issue was discovered in the Linux kernel before 6.3.4. fs/ksmbd/smb2pdu.c in ksmbd does not properly check the UserName value because it does not consider the address of security buffer, leading to an out-of-bounds read.
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Linux Kernel | >=5.15<5.15.113 | |
Linux Kernel | >=5.16<6.1.30 | |
Linux Kernel | >=6.2<6.3.4 | |
netapp solidfire \& hci management node | ||
netapp solidfire \& hci storage node | ||
netapp h300s | ||
netapp h410s | ||
netapp h500s | ||
netapp h700s | ||
Linux Kernel | <6.3.4 | |
debian/linux | 5.10.223-1 5.10.226-1 6.1.123-1 6.1.128-1 6.12.12-1 6.12.13-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-38428 is considered a high severity vulnerability due to its potential for causing out-of-bounds reads in the Linux kernel.
To fix CVE-2023-38428, update your Linux kernel to a version later than 6.3.4 or to one of the specified patched versions like 5.10.223-1 or 6.1.123-1.
CVE-2023-38428 affects various versions of the Linux kernel prior to 6.3.4 and certain NetApp SolidFire and HCI management nodes.
CVE-2023-38428 involves inadequate checks of the UserName value leading to an out-of-bounds read, which could be exploited for information disclosure.
CVE-2023-38428 was last updated on November 29, 2024.