peter bassill · operator
$ cve CVE-2023-38426 JSON

CVE-2023-38426

9.1
CRITICAL · CVSS 3.1 · EPSS 3% (pctl 87)

In your normal cycle

Critical by CVSS (9.1), but no sign of active exploitation.

Description

An issue was discovered in the Linux kernel before 6.3.4. ksmbd has an out-of-bounds read in smb2_find_context_vals when create_context's name_len is larger than the tag length.

Scoring

CVSS9.1 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
EPSS3.04% — more likely to be exploited than 87% of all CVEs
WeaknessCWE-125
On CISA KEVno
Public exploitnone known
Published2023-07-18
Last modified2026-06-17

Affected (7)

VendorProduct
linuxlinux kernel
netapph300s
netapph410s
netapph500s
netapph700s
netappsolidfire \& hci management node
netappsolidfire \& hci storage node

References

→ the Explorer  ·  watch your stack  ·  NVD