First published: Mon Jul 17 2023(Updated: )
An issue was discovered in the Linux kernel before 6.3.4. fs/ksmbd/smb2pdu.c in ksmbd does not properly check the UserName value because it does not consider the address of security buffer, leading to an out-of-bounds read.
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Linux Kernel | <6.3.4 | |
Linux Kernel | >=5.15<5.15.113 | |
Linux Kernel | >=5.16<6.1.30 | |
Linux Kernel | >=6.2<6.3.4 | |
NetApp SolidFire & HCI Management Node | ||
NetApp SolidFire & HCI Storage Node | ||
NetApp H300S Firmware | ||
NetApp H410S Firmware | ||
NetApp H500e Firmware | ||
NetApp H700S | ||
debian/linux | 5.10.223-1 5.10.234-1 6.1.129-1 6.1.128-1 6.12.20-1 6.12.21-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-38428 is considered a high severity vulnerability due to its potential for causing out-of-bounds reads in the Linux kernel.
To fix CVE-2023-38428, update your Linux kernel to a version later than 6.3.4 or to one of the specified patched versions like 5.10.223-1 or 6.1.123-1.
CVE-2023-38428 affects various versions of the Linux kernel prior to 6.3.4 and certain NetApp SolidFire and HCI management nodes.
CVE-2023-38428 involves inadequate checks of the UserName value leading to an out-of-bounds read, which could be exploited for information disclosure.
CVE-2023-38428 was last updated on November 29, 2024.