CVE-2023-38432: Critical severity Linux Linux kernel vulnerability
An issue was discovered in the Linux kernel before 6.3.10. fs/smb/server/smb2misc.c in ksmbd does not validate the relationship between the command payload size and the RFC1002 length specification, leading to an out-of-bounds read.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.25-1 - Upgrade
Upgrade
Linux kernel (ksmbd)to a version that resolves this vulnerability.Fixed in 6.3.10
Event History
Frequently Asked Questions
What is the severity of CVE-2023-38432?
CVE-2023-38432 is classified as a medium severity vulnerability due to its potential to lead to out-of-bounds reads in the Linux kernel.
How do I fix CVE-2023-38432?
To address CVE-2023-38432, upgrade to Linux kernel versions 6.3.10 or later, or apply available patches from your distribution.
What systems are affected by CVE-2023-38432?
CVE-2023-38432 affects Linux kernel versions before 6.3.10, including specific versions in the 5.15 and 5.16 series, as well as several NetApp appliances.
Is my Linux kernel version safe from CVE-2023-38432?
If your Linux kernel version is 6.3.10 or above, you are not vulnerable to CVE-2023-38432.
What type of vulnerability is CVE-2023-38432?
CVE-2023-38432 is a memory corruption issue resulting from improper validation of command payload sizes in the SMB protocol implementation.