Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-4130

24
FAUCET Score

CVE-2023-4130 is a medium-severity vulnerability in the Linux kernel's ksmbd module, affecting the handling of extended attribute (EA) buffers. Specifically, it involves incorrect validation of the next EA buffer length during FILE_FULL_EA_INFORMATION requests, potentially leading to a denial of service. The vulnerability has a CVSS score of 5.5 (MEDIUM) with a local attack vector and low attack complexity, impacting availability. There is no evidence of active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage regarding this flaw.

Impacted Technologies

VendorProductVersion(s)CPE
>= 5.15, < 5.15.127CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.16, < 6.1.46CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 6.2, < 6.4.11CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
6.5CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:6.5:rc1:*:*:*:*:*:*
6.5CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:6.5:rc2:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.23%
Probability of exploitation in next 30 days
EPSS Percentile
14.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0023 is in the 62nd percentile among its peer group of 15,940 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

redhatCVE-2023-4130Moderate

kernel: ksmbd: fix wrong next length validation of ea buffer in smb2_set_ea()

Aug 16, 2025

References

git.kernel.org / stable/c/4bf629262f9118ee91b1c3a518ebf2b3bcb22180
Patch
git.kernel.org / stable/c/79ed288cef201f1f212dfb934bcaac75572fb8f6
Patch
git.kernel.org / stable/c/aeb974907642be095e38ecb1a400ca583958b2b0
Patch
git.kernel.org / stable/c/f339d76a3a972601d0738b881b099d49ebbdc3a2
Patch