CVE-2023-38429: Critical severity Linux Linux kernel vulnerability
An issue was discovered in the Linux kernel before 6.3.4. fs/ksmbd/connection.c in ksmbd has an off-by-one error in memory allocation (because of ksmbdsmb2checkmessage) that may lead to out-of-bounds access.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.25-1 - Upgrade
Upgrade
Linux kernel ksmbdto a version that resolves this vulnerability.Fixed in 6.3.4
Event History
Frequently Asked Questions
What is the severity of CVE-2023-38429?
CVE-2023-38429 has a medium severity rating due to the potential for out-of-bounds access caused by an off-by-one error in memory allocation.
What versions of the Linux kernel are affected by CVE-2023-38429?
CVE-2023-38429 affects Linux kernel versions prior to 6.3.4, specifically versions 5.15 to 5.15.113, 5.16 to 6.1.30, and 6.2 to 6.3.4.
How do I fix CVE-2023-38429?
To fix CVE-2023-38429, upgrade the Linux kernel to version 6.3.4 or later, or the specified remedial versions for earlier kernels.
What type of vulnerability is CVE-2023-38429?
CVE-2023-38429 is a memory corruption vulnerability due to an off-by-one error in the Linux kernel's ksmbd module.
Can CVE-2023-38429 lead to exploitation by attackers?
Yes, CVE-2023-38429 can potentially allow attackers to exploit the vulnerability for unauthorized access or system crashes due to out-of-bounds memory access.