Home

Description

In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate command request size In commit 2b9b8f3b68ed ("ksmbd: validate command payload size"), except for SMB2_OPLOCK_BREAK_HE command, the request size of other commands is not checked, it's not expected. Fix it by add check for request size of other commands.

PUBLISHED Reserved 2023-08-24 | Published 2025-08-16 | Updated 2025-08-16 | Assigner Linux

Product status

Default status
unaffected

35f450f54dca1519bb24faacd0428db09f89a11f before 595679098bdcdbfbba91ebe07a2f7f208df93870
affected

9650cf70ec9d94ff34daa088b643229231723c26 before c6bef3bc30fd4a175aef846b7d928a6c40d091cd
affected

2b9b8f3b68edb3d67d79962f02e26dbb5ae3808d before ff7236b66d69582f90cf5616e63cfc3dc18142bb
affected

2b9b8f3b68edb3d67d79962f02e26dbb5ae3808d before 5aa4fda5aa9c2a5a7bac67b4a12b089ab81fee3c
affected

768caf4019f0391c0b6452afe34cea1704133f7b
affected

Default status
affected

6.4
affected

Any version before 6.4
unaffected

5.15.127
unaffected

6.1.46
unaffected

6.4.11
unaffected

6.5
unaffected

References

git.kernel.org/...c/595679098bdcdbfbba91ebe07a2f7f208df93870

git.kernel.org/...c/c6bef3bc30fd4a175aef846b7d928a6c40d091cd

git.kernel.org/...c/ff7236b66d69582f90cf5616e63cfc3dc18142bb

git.kernel.org/...c/5aa4fda5aa9c2a5a7bac67b4a12b089ab81fee3c

cve.org (CVE-2023-4515)

nvd.nist.gov (CVE-2023-4515)

Download JSON