High [CVE-2023-6610] Kernel: oob access in smb2_dump_detail
This high-severity Red Hat Linux advisory covers CVE-2023-6610 affecting Red Hat Enterprise Linux 8.6 Extended Update Support, Red Hat Enterprise Linux 8.8 Extended Update Support, Red Hat Enterprise Linux 9.2 Extended Update Support.
Android app · Google Play
Monitor future Red Hat Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Summary
An out-of-bounds read vulnerability was found in smb2_dump_detail in fs/smb/client/smb2ops.c in the Linux Kernel. This issue could allow a local attacker to crash the system or leak internal kernel information.
Red Hat severity: Moderate — CVSS 7.1 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H). Weakness: CWE-125.
Affected Red Hat products: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 8.6 Extended Update Support; Red Hat Enterprise Linux 8.8 Extended Update Support; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 9.2 Extended Update Support; Red Hat Virtualization 4 for Red Hat Enterprise Linux 8; RHOL-5.8-RHEL-9; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7.
Will not fix / out of support: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Red Hat fixing advisory: RHSA-2024:0881, RHSA-2024:0897, RHSA-2024:0724, RHSA-2024:1404, RHSA-2024:1248, RHSA-2024:0723, RHSA-2024:0725, RHSA-2024:2094.
Affected products named by the advisory: Red Hat package: kernel-rt.
Affected versions
No affected-version range was extracted from the source record. The vendor advisory is authoritative — check it before change work.
Official advisory · high-confidence parse· fetched 57 minutes ago·verify at source
- kernel-rt-0:4.18.0-513.18.1.rt7.320.el8_9
- kernel-0:4.18.0-513.18.1.el8_9
- kernel-0:4.18.0-372.91.1.el8_6
- kernel-0:4.18.0-477.51.1.el8_8
- kernel-0:5.14.0-362.24.1.el9_3
- kernel-0:5.14.0-284.52.1.el9_2
- kernel-rt-0:5.14.0-284.52.1.rt14.337.el9_2
- openshift-logging/cluster-logging-operator-bundle:v5.8.6-22
- openshift-logging/cluster-logging-rhel9-operator:v5.8.6-11
- openshift-logging/elasticsearch6-rhel9:v6.8.1-407
- openshift-logging/elasticsearch-operator-bundle:v5.8.6-19
- openshift-logging/elasticsearch-proxy-rhel9:v1.0.0-479
- openshift-logging/elasticsearch-rhel9-operator:v5.8.6-7
- openshift-logging/eventrouter-rhel9:v0.4.0-247
- openshift-logging/fluentd-rhel9:v5.8.6-5
- openshift-logging/log-file-metric-exporter-rhel9:v1.1.0-227
- openshift-logging/logging-curator5-rhel9:v5.8.1-470
- openshift-logging/logging-loki-rhel9:v2.9.6-14
- openshift-logging/logging-view-plugin-rhel9:v5.8.6-2
- openshift-logging/loki-operator-bundle:v5.8.6-24
- openshift-logging/loki-rhel9-operator:v5.8.6-10
- openshift-logging/lokistack-gateway-rhel9:v0.1.0-525
- openshift-logging/opa-openshift-rhel9:v0.1.0-224
- openshift-logging/vector-rhel9:v0.28.1-56
- RHSA-2024:0881
- RHSA-2024:0897
- RHSA-2024:0724
- RHSA-2024:1404
- RHSA-2024:1248
- RHSA-2024:0723
- RHSA-2024:0725
- RHSA-2024:2094
Official advisory · high-confidence parse· fetched 57 minutes ago·verify at source
Mitigation checklist
- To mitigate this issue, prevent module cifs from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically.
Official advisory · high-confidence parse· fetched 57 minutes ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.