CVE-2023-4515

MEDIUM

Linux Kernel 5.15.121-5.15.126 - Unauthenticated Denial of Service via SMB2 Command Request Size Validation

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate command request size In commit 2b9b8f3b68ed ("ksmbd: validate command payload size"), except for SMB2_OPLOCK_BREAK_HE command, the request size of other commands is not checked, it's not expected. Fix it by add check for request size of other commands.

Scores

CVSS v3 5.5
EPSS 0.0014
EPSS Percentile 4.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

Status published
Products (20)
linux/Kernel < 5.15.127linux
linux/Kernel 5.16.0 - 6.1.46linux
linux/Kernel 6.2.0 - 6.4.11linux
Linux/Linux < 6.4
Linux/Linux 2b9b8f3b68edb3d67d79962f02e26dbb5ae3808d - 5aa4fda5aa9c2a5a7bac67b4a12b089ab81fee3c
Linux/Linux 2b9b8f3b68edb3d67d79962f02e26dbb5ae3808d - ff7236b66d69582f90cf5616e63cfc3dc18142bb
Linux/Linux 35f450f54dca1519bb24faacd0428db09f89a11f - 595679098bdcdbfbba91ebe07a2f7f208df93870
Linux/Linux 5.15.121 - 5.15.127
Linux/Linux 5.15.127 - 5.15.*
Linux/Linux 6.1.36 - 6.1.46
... and 10 more
Published Aug 16, 2025
Tracked Since Feb 18, 2026