-

CVE-2023-3865

In the Linux kernel, the following vulnerability has been resolved:

ksmbd: fix out-of-bound read in smb2_write

ksmbd_smb2_check_message doesn't validate hdr->NextCommand. If
->NextCommand is bigger than Offset + Length of smb2 write, It will
allow oversized smb2 write length. It will cause OOB read in smb2_write.

Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
This information is available to logged-in users.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
VendorLinux
Product Linux
Default Statusunaffected
Version < 3813eee5154d6a4c5875cb4444cb2b63bac8947f
Version 0626e6641f6b467447c81dd7678a69c66f7746cf
Status affected
Version < c86211159bc3178b891e0d60e586a32c7b6a231b
Version 0626e6641f6b467447c81dd7678a69c66f7746cf
Status affected
Version < 58a9c41064df27632e780c5a3ae3e0e4284957d1
Version 0626e6641f6b467447c81dd7678a69c66f7746cf
Status affected
Version < 5fe7f7b78290638806211046a99f031ff26164e1
Version 0626e6641f6b467447c81dd7678a69c66f7746cf
Status affected
VendorLinux
Product Linux
Default Statusaffected
Version 5.15
Status affected
Version < 5.15
Version 0
Status unaffected
Version <= 5.15.*
Version 5.15.121
Status unaffected
Version <= 6.1.*
Version 6.1.36
Status unaffected
Version <= 6.3.*
Version 6.3.10
Status unaffected
Version <= *
Version 6.4
Status unaffected
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.04% 0.095
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string