VYPR
High severity7.1NVD Advisory· Published Nov 3, 2023· Updated Jun 17, 2026

CVE-2023-1194

CVE-2023-1194

Description

An out-of-bounds (OOB) memory read flaw was found in parse_lease_state in the KSMBD implementation of the in-kernel samba server and CIFS in the Linux kernel. When an attacker sends the CREATE command with a malformed payload to KSMBD, due to a missing check of NameOffset in the parse_lease_state() function, the create_context object can access invalid memory.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

14
  • Red Hat/Enterprise Linux Servercpe-rescue4 versions
    cpe:/o:redhat:enterprise_linux:6+ 3 more
    • cpe:/o:redhat:enterprise_linux:6
    • cpe:/o:redhat:enterprise_linux:7
    • cpe:/o:redhat:enterprise_linux:8
    • cpe:/o:redhat:enterprise_linux:9
  • cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*
  • Linux/Kernel7 versions
    cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*+ 6 more
    • cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*range: >=5.15,<5.15.145
    • cpe:2.3:o:linux:linux_kernel:6.4:rc1:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:6.4:rc2:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:6.4:rc3:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:6.4:rc4:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:6.4:rc5:*:*:*:*:*:*
    • (no CPE)

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.