Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate command request size In commit 2b9b8f3b68ed ("ksmbd: validate command payload size"), except for SMB2_OPLOCK_BREAK_HE command, the request size of other commands is not checked, it's not expected. Fix it by add check for request size of other commands.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 5.15.121, < 5.15.127 |
References
- https://git.kernel.org/stable/c/595679098bdcdbfbba91ebe07a2f7f208df93870Patch
- https://git.kernel.org/stable/c/5aa4fda5aa9c2a5a7bac67b4a12b089ab81fee3cPatch
- https://git.kernel.org/stable/c/c6bef3bc30fd4a175aef846b7d928a6c40d091cdPatch
- https://git.kernel.org/stable/c/ff7236b66d69582f90cf5616e63cfc3dc18142bbPatch
FAQ
What is CVE-2023-4515?
CVE-2023-4515 is a vulnerability with a CVSS score of 5.5 (MEDIUM). In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate command request size In commit 2b9b8f3b68ed ("ksmbd: validate command payload size"), except for SMB2_OPLOCK_BREAK...
How severe is CVE-2023-4515?
CVE-2023-4515 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-4515?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.