CVE-2023-4515

MEDIUM EPSS 3.3%
Published Aug 16, 202510mo ago · Modified Jun 17, 20261w ago
5.5 CVSS 3.1
Medium
Find Similar
Published Aug 16, 2025 10mo ago
Last Modified Jun 17, 2026 1w ago

Description

In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate command request size In commit 2b9b8f3b68ed ("ksmbd: validate command payload size"), except for SMB2_OPLOCK_BREAK_HE command, the request size of other commands is not checked, it's not expected. Fix it by add check for request size of other commands.

CVSS Details

Base Score
5.5
Exploitability
1.8
Impact
3.6
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality None
Integrity None
Availability High

Threat Intelligence

EPSS Exploit Probability
3.3% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Affected Products 10

VendorProductVersionRange
linuxlinux_kernel*≥5.15.121  –  <5.15.127
linuxlinux_kernel*≥6.1.36  –  <6.1.46
linuxlinux_kernel*≥6.3.10  –  <6.4
linuxlinux_kernel*≥6.4.1  –  <6.4.11
linuxlinux_kernel6.4any
linuxlinux_kernel6.5any
linuxlinux_kernel6.5any
linuxlinux_kernel6.5any
linuxlinux_kernel6.5any
linuxlinux_kernel6.5any

References 4

  • git.kernel.org https://git.kernel.org/stable/c/595679098bdcdbfbba91ebe07a2f7f208df93870
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/5aa4fda5aa9c2a5a7bac67b4a12b089ab81fee3c
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/c6bef3bc30fd4a175aef846b7d928a6c40d091cd
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/ff7236b66d69582f90cf5616e63cfc3dc18142bb
    Patch

Remediation

  • git.kernel.org https://git.kernel.org/stable/c/595679098bdcdbfbba91ebe07a2f7f208df93870
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/5aa4fda5aa9c2a5a7bac67b4a12b089ab81fee3c
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/c6bef3bc30fd4a175aef846b7d928a6c40d091cd
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/ff7236b66d69582f90cf5616e63cfc3dc18142bb
    Patch