CVE-2023-1194 is an out-of-bounds memory read flaw in the KSMBD implementation of the in-kernel Samba server and CIFS in the Linux kernel, affecting Fedora and other Linux distributions. An authenticated attacker can trigger this vulnerability by sending a malformed CREATE command, leading to invalid memory access. With a CVSS score of 8.1 (HIGH), this vulnerability allows for high confidentiality and availability impacts with low attack complexity. There is currently no public exploit code available, nor is it listed on the CISA KEV catalog, indicating no active exploitation. Community discussion and media coverage are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.15, < 5.15.145CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.16, < 6.1.34CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.2, < 6.3.8CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
6.4CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:6.4:rc1:*:*:*:*:*:* | ||
6.4CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:6.4:rc2:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.