CVE-2023-38429

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Jul 18, 2023
Updated: Jan 3, 2025
CWE ID 193

Summary

CVE-2023-38429 is a vulnerability affecting Linux kernels prior to version 6.3.4. In the file "fs/ksmbd/connection.c" of the ksmbd component, an off-by-one error occurs during memory allocation due to the function "ksmbd_smb2_check_message." This issue may result in out-of-bounds memory access, potentially leading to exploitation and security compromises.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share