CVE-2023-3867 – Kerberos SMB Out-of-Bounds Read Vulnerability

The following table lists the changes that have been made to the
CVE-2023-3867 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by 416baaa9-dc9f-4396-8d5f-8c081fb06d67

    Aug. 16, 2025

    Action Type Old Value New Value
    Added Description In the Linux kernel, the following vulnerability has been resolved:

    ksmbd: fix out of bounds read in smb2_sess_setup

    ksmbd does not consider the case of that smb2 session setup is
    in compound request. If this is the second payload of the compound,
    OOB read issue occurs while processing the first payload in
    the smb2_sess_setup().

    Added Reference https://git.kernel.org/stable/c/2ba03cecb12ac7ac9e0170e251543c56832d9959
    Added Reference https://git.kernel.org/stable/c/676392184785ace61e939831e7ca44a03d438c3b
    Added Reference https://git.kernel.org/stable/c/98422bdd4cb3ca4d08844046f6507d7ec2c2b8d8
    Added Reference https://git.kernel.org/stable/c/ef572ffa8eb44111eed2925fbb2adca78bdcbf61
Share the Post:

Related Posts