An issue was discovered in the Linux kernel before 6.3.8. fs/smb/server/smb2pdu.c in ksmbd has an integer underflow and out-of-bounds read in deassemble_neg_contexts.
                
            References
                    Configurations
                    Configuration 1 (hide)
            
            
  | 
    
Configuration 2 (hide)
            
            
  | 
    
History
                    21 Nov 2024, 08:13
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.3.8 - Release Notes | |
| References | () https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/fs/smb/server?id=f1a411873c85b642f13b01f21b534c2bab81fc1b - Patch | |
| References | () https://security.netapp.com/advisory/ntap-20230824-0011/ - Third Party Advisory | 
17 Nov 2023, 18:55
| Type | Values Removed | Values Added | 
|---|---|---|
| CPE | cpe:2.3:h:netapp:h700s:-:*:*:*:*:*:*:* cpe:2.3:h:netapp:h500s:-:*:*:*:*:*:*:* cpe:2.3:h:netapp:h410s:-:*:*:*:*:*:*:* cpe:2.3:h:netapp:h300s:-:*:*:*:*:*:*:*  | 
|
| References | (CONFIRM) https://security.netapp.com/advisory/ntap-20230824-0011/ - Third Party Advisory | |
| First Time | 
        
        Netapp
         Netapp h410s Netapp h700s Netapp h500s Netapp h300s  | 
24 Aug 2023, 19:15
| Type | Values Removed | Values Added | 
|---|---|---|
| References | 
        
        
  | 
27 Jul 2023, 16:09
| Type | Values Removed | Values Added | 
|---|---|---|
| CPE | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | |
| CWE | CWE-191 CWE-125  | 
|
| References | (MISC) https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/fs/smb/server?id=f1a411873c85b642f13b01f21b534c2bab81fc1b - Patch | |
| References | (MISC) https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.3.8 - Release Notes | |
| CVSS | 
        v2 :  v3 :  | 
    
        v2 : unknown
         v3 : 9.8  | 
| First Time | 
        
        Linux linux Kernel
         Linux  | 
18 Jul 2023, 00:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2023-07-18 00:15
Updated : 2025-05-05 16:15
NVD link : CVE-2023-38427
Mitre link : CVE-2023-38427
CVE.ORG link : CVE-2023-38427
JSON object : View
Products Affected
                netapp
- h300s
 - h700s
 - h410s
 - h500s
 
linux
- linux_kernel
 
