Skip to content
VulniPulse
High7.1Vendor: MediumRed Hat Linux

High [CVE-2023-6610] Kernel: oob access in smb2_dump_detail

This high-severity Red Hat Linux advisory covers CVE-2023-6610 affecting Red Hat Enterprise Linux 8.6 Extended Update Support, Red Hat Enterprise Linux 8.8 Extended Update Support, Red Hat Enterprise Linux 9.2 Extended Update Support.

CVE-2023-6610 Published Dec 8, 2023Updated by vendor Dec 4, 2023
Affected products & platforms
Red Hat LinuxLinux Kernel
Open vendor advisory

Android app · Google Play

Monitor future Red Hat Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery

Summary

An out-of-bounds read vulnerability was found in smb2_dump_detail in fs/smb/client/smb2ops.c in the Linux Kernel. This issue could allow a local attacker to crash the system or leak internal kernel information.

Red Hat severity: Moderate — CVSS 7.1 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H). Weakness: CWE-125.

Affected Red Hat products: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 8.6 Extended Update Support; Red Hat Enterprise Linux 8.8 Extended Update Support; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 9.2 Extended Update Support; Red Hat Virtualization 4 for Red Hat Enterprise Linux 8; RHOL-5.8-RHEL-9; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7.

Will not fix / out of support: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Red Hat fixing advisory: RHSA-2024:0881, RHSA-2024:0897, RHSA-2024:0724, RHSA-2024:1404, RHSA-2024:1248, RHSA-2024:0723, RHSA-2024:0725, RHSA-2024:2094.

Affected products named by the advisory: Red Hat package: kernel-rt.

Affected versions

No affected-version range was extracted from the source record. The vendor advisory is authoritative — check it before change work.

Official advisory · high-confidence parse· fetched 57 minutes ago·verify at source

Fixed versions
  • kernel-rt-0:4.18.0-513.18.1.rt7.320.el8_9
  • kernel-0:4.18.0-513.18.1.el8_9
  • kernel-0:4.18.0-372.91.1.el8_6
  • kernel-0:4.18.0-477.51.1.el8_8
  • kernel-0:5.14.0-362.24.1.el9_3
  • kernel-0:5.14.0-284.52.1.el9_2
  • kernel-rt-0:5.14.0-284.52.1.rt14.337.el9_2
  • openshift-logging/cluster-logging-operator-bundle:v5.8.6-22
  • openshift-logging/cluster-logging-rhel9-operator:v5.8.6-11
  • openshift-logging/elasticsearch6-rhel9:v6.8.1-407
  • openshift-logging/elasticsearch-operator-bundle:v5.8.6-19
  • openshift-logging/elasticsearch-proxy-rhel9:v1.0.0-479
  • openshift-logging/elasticsearch-rhel9-operator:v5.8.6-7
  • openshift-logging/eventrouter-rhel9:v0.4.0-247
  • openshift-logging/fluentd-rhel9:v5.8.6-5
  • openshift-logging/log-file-metric-exporter-rhel9:v1.1.0-227
  • openshift-logging/logging-curator5-rhel9:v5.8.1-470
  • openshift-logging/logging-loki-rhel9:v2.9.6-14
  • openshift-logging/logging-view-plugin-rhel9:v5.8.6-2
  • openshift-logging/loki-operator-bundle:v5.8.6-24
  • openshift-logging/loki-rhel9-operator:v5.8.6-10
  • openshift-logging/lokistack-gateway-rhel9:v0.1.0-525
  • openshift-logging/opa-openshift-rhel9:v0.1.0-224
  • openshift-logging/vector-rhel9:v0.28.1-56
  • RHSA-2024:0881
  • RHSA-2024:0897
  • RHSA-2024:0724
  • RHSA-2024:1404
  • RHSA-2024:1248
  • RHSA-2024:0723
  • RHSA-2024:0725
  • RHSA-2024:2094

Official advisory · high-confidence parse· fetched 57 minutes ago·verify at source

Mitigation checklist

Recommended fix / mitigation
  • To mitigate this issue, prevent module cifs from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically.

Official advisory · high-confidence parse· fetched 57 minutes ago·verify at source

Discussion(0)

No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.

Sign in to join the discussion.