-

CVE-2023-3867

In the Linux kernel, the following vulnerability has been resolved:

ksmbd: fix out of bounds read in smb2_sess_setup

ksmbd does not consider the case of that smb2 session setup is
in compound request. If this is the second payload of the compound,
OOB read issue occurs while processing the first payload in
the smb2_sess_setup().

Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
This information is available to logged-in users.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
VendorLinux
Product Linux
Default Statusunaffected
Version < 676392184785ace61e939831e7ca44a03d438c3b
Version 0626e6641f6b467447c81dd7678a69c66f7746cf
Status affected
Version < ef572ffa8eb44111eed2925fbb2adca78bdcbf61
Version 0626e6641f6b467447c81dd7678a69c66f7746cf
Status affected
Version < 2ba03cecb12ac7ac9e0170e251543c56832d9959
Version 0626e6641f6b467447c81dd7678a69c66f7746cf
Status affected
Version < 98422bdd4cb3ca4d08844046f6507d7ec2c2b8d8
Version 0626e6641f6b467447c81dd7678a69c66f7746cf
Status affected
VendorLinux
Product Linux
Default Statusaffected
Version 5.15
Status affected
Version < 5.15
Version 0
Status unaffected
Version <= 5.15.*
Version 5.15.145
Status unaffected
Version <= 6.1.*
Version 6.1.40
Status unaffected
Version <= 6.4.*
Version 6.4.5
Status unaffected
Version <= *
Version 6.5
Status unaffected
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.6% 0.684
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string