An out-of-bounds (OOB) memory read flaw was found in parseleasestate in the KSMBD implementation of the in-kernel samba server and CIFS in the Linux kernel. When an attacker sends the CREATE command with a malformed payload to KSMBD, due to a missing check of NameOffset in the parse_lease_state() function, the create_context object can access invalid memory.
[
{
"events": [
{
"introduced": "5.15"
},
{
"fixed": "5.15.145"
}
]
},
{
"events": [
{
"introduced": "5.16"
},
{
"fixed": "6.1.34"
}
]
},
{
"events": [
{
"introduced": "6.2"
},
{
"fixed": "6.3.8"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "6.4-rc1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "6.4-rc2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "6.4-rc3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "6.4-rc4"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "6.4-rc5"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "37"
}
]
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-1194.json"