RHSA-2024:0723Vendor advisory
https://access.redhat.com/errata/RHSA-2024:0723 CVE-2023-6606
HIGH
Kernel: out-of-bounds read vulnerability in smbcalcsize
Record summary
CVE-2023-6606 has a selected CVSS score of 7.1 (high).
Description
An out-of-bounds read vulnerability was found in smbCalcSize in fs/smb/client/netmisc.c in the Linux Kernel. This issue could allow a local attacker to crash the system or leak internal kernel information.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 11, 2023 · Source: CVE List
Affected products and versions
Showing 12 of 29| Product | Source | Version range | Status |
|---|---|---|---|
Default status: affected | CVE List | v5.8.6-22 to < * | unaffected |
Default status: affected | CVE List | v5.8.6-11 to < * | unaffected |
Default status: affected | CVE List | v5.8.6-19 to < * | unaffected |
Default status: affected | CVE List | v1.0.0-479 to < * | unaffected |
Default status: affected | CVE List | v5.8.6-7 to < * | unaffected |
Default status: affected | CVE List | v6.8.1-407 to < * | unaffected |
Default status: affected | CVE List | v0.4.0-247 to < * | unaffected |
Default status: affected | CVE List | v5.8.6-5 to < * | unaffected |
Default status: affected | CVE List | v1.1.0-227 to < * | unaffected |
Default status: affected | CVE List | v5.8.1-470 to < * | unaffected |
Default status: affected | CVE List | v2.9.6-14 to < * | unaffected |
Default status: affected | CVE List | v5.8.6-2 to < * | unaffected |
References
Showing 12 of 14RHSA-2024:0725Vendor advisory
https://access.redhat.com/errata/RHSA-2024:0725 RHSA-2024:0881Vendor advisory
https://access.redhat.com/errata/RHSA-2024:0881 RHSA-2024:0897Vendor advisory
https://access.redhat.com/errata/RHSA-2024:0897 RHSA-2024:1188Vendor advisory
https://access.redhat.com/errata/RHSA-2024:1188 RHSA-2024:1248Vendor advisory
https://access.redhat.com/errata/RHSA-2024:1248 RHSA-2024:1404Vendor advisory
https://access.redhat.com/errata/RHSA-2024:1404 RHSA-2024:2094Vendor advisory
https://access.redhat.com/errata/RHSA-2024:2094 access.redhat.comvdb entry
https://access.redhat.com/security/cve/CVE-2023-6606 bugzilla.kernel.org
https://bugzilla.kernel.org/show_bug.cgi?id=218218 RHBZ#2253611issue tracking
https://bugzilla.redhat.com/show_bug.cgi?id=2253611 lists.debian.org
https://lists.debian.org/debian-lts-announce/2024/01/msg00004.html