CVE-2023-6610
Aliases:UBUNTU-CVE-2023-6610DEBIAN-CVE-2023-6610CGA-2445-gc5c-48mrCGA-286q-72wx-23hpCGA-28rx-vcf4-5p3pCGA-2cmw-7jrx-vjc9CGA-2mgc-wqmv-pc27CGA-2w76-4qx9-cwfrCGA-326m-cxc2-77gvCGA-36qw-m3m3-wwp6CGA-386w-42pf-m2xxCGA-3fwq-pfpg-f4cgCGA-3jhc-g9v8-qm6pCGA-3jqv-hphq-pp8rCGA-3mqf-xc7w-qx37CGA-3rg7-xwfv-hr5gCGA-3rpv-mwg3-25xxCGA-42qp-9h4j-4m9gCGA-4j6f-rf4g-frwqCGA-4phw-5hqg-hmr8CGA-4vxw-m956-5f8cCGA-4wf8-8wm5-wcwfCGA-4wq7-2hfw-f5p4CGA-526q-rm8j-7c57CGA-5cjf-jrfj-hq5rCGA-5g43-gccx-9vgqCGA-5g93-qf2c-rx6mCGA-5rr3-w6fc-g336CGA-5vmw-f7v2-52pqCGA-5vr3-pqhp-2wjvCGA-5w47-wpv7-h926CGA-5x75-9657-cprrCGA-6689-76fq-7x2gCGA-692w-4p99-w777CGA-6q5c-5p4g-m6vpCGA-6v9w-f6cv-7hgfCGA-6wr4-rrpr-5rcfCGA-6wx2-f82h-vc32CGA-74wc-q6cq-rhvjCGA-7v4p-8f8v-47h6CGA-7ww7-f94c-p2hxCGA-8fr6-8fx6-c376CGA-8fw5-j7j7-5cx6CGA-8wm2-jh63-j479CGA-8xfg-7xhg-mm4mCGA-9538-jqqq-89gxCGA-97jp-25p5-cp69CGA-97xm-f959-g4w4CGA-993h-j3gp-5459CGA-9fwf-xw97-fvrfCGA-9g7w-4vv5-hwp7CGA-9hjg-c843-5x49CGA-9p35-284x-xh92CGA-9r8p-x524-rjgpCGA-c83f-2q5h-g7f5CGA-cfx8-5g5c-c6pjCGA-cqhq-whqv-58c8CGA-cv8f-6v4f-f2gjCGA-fpgj-56gc-927fCGA-fr9p-gg76-hj23CGA-frjh-6625-xmcqCGA-gfhv-3v9w-vm9mCGA-gw2r-258c-99rvCGA-h5wg-3gw5-9783CGA-hc76-7xp3-v42wCGA-hgg3-9gcj-75gcCGA-hjfx-wvwv-wf7gCGA-hqf8-pxm5-p76rCGA-hrgm-6ggf-jmp7CGA-hrx9-mpw6-r4rjCGA-j7h2-ff6w-6f3cCGA-j9jv-89rh-r6qjCGA-jc7j-j9qx-4f3jCGA-jf3v-fc7p-vphvCGA-jmwh-wrrf-crhxCGA-jv3j-9jpj-688xCGA-m3m6-jgj4-4rfmCGA-m59m-f63w-g3w8CGA-mmg6-9qxq-r6v7CGA-mv74-x35r-pj26CGA-mx57-534p-88grCGA-p33q-486r-36q8CGA-pg4v-4hwh-jcm4CGA-phvf-fjwh-q3p8CGA-pqhj-5376-33q6CGA-prjx-m2mx-38jfCGA-q632-g4r6-v3qwCGA-qc99-r2q5-hh34CGA-qg6h-q7f5-jprjCGA-qhrx-9wmp-433wCGA-qhwq-c353-62qmCGA-qmhj-p5xq-ph67CGA-qx65-8vx9-cc5wCGA-r2mp-v74v-8fg2CGA-r359-j3rh-qxq3CGA-r4xr-6cc6-w3qcCGA-r5wj-545g-xxc9CGA-r784-fxvm-q5p8CGA-r9j4-hrxh-37v9CGA-rgvm-fg2g-7pwrCGA-rhh8-2pq6-664vCGA-rj4x-hwh7-hp89CGA-rqjg-9j2c-h4rxCGA-v8hq-4hm9-9xxjCGA-vgvx-j4g8-mhppCGA-vj42-59v6-gjg3CGA-vj63-4756-vqmvCGA-vr3w-jv9c-w5h8CGA-vwhx-rx3c-3cvcCGA-w3h8-8955-p9m8CGA-w42v-9h32-qhc7CGA-w723-x7fx-mqh6CGA-wfxj-6672-rw24CGA-x45h-gjqj-pj4hCGA-x553-33qm-mfmjCGA-x974-9gw3-rmj9CGA-xjpf-vmjg-cq4rCGA-xr78-vchf-c397CGA-5rpp-grxp-jw38CGA-w7c2-vjm6-894mCGA-5mmf-fff9-9xjvCGA-62vq-6rjh-84qpCGA-887h-prh3-xh6jCGA-9g2p-5983-w88gCGA-9vqm-cvjp-6w8wCGA-ff8j-xxxc-8gj8CGA-hc9p-766h-qgv4CGA-j947-g356-vv7cCGA-jfpx-qrp3-h6xhCGA-m325-mr8r-rg9xCGA-m6rh-c22h-6vw6CGA-p56w-grxv-ghfhCGA-qcq8-9vjq-mvw2CGA-qw2p-m5xj-vpf7CGA-cgf4-3h3v-p889CGA-gqwq-hwm6-gw3fCGA-pwqq-hxfr-g8qrCGA-rjgv-663w-99qhCGA-rw58-3mp3-hcfxCGA-vxv7-2xjg-9xpmCGA-wv7v-x59r-cwg9CGA-8cc2-qw39-78h2CGA-4p66-jf74-vpgfCGA-4x4j-h639-7h9jCGA-7j98-5vp9-55j4
Advisory lineage Upstream: 0 Downstream: 31
Modified
Published: 08 Dec 2023, 16:58
Last modified:25 Aug 2026, 18:02
Vulnerability Summary
Overall Risk (default)
medium
38/100 CVSS Score
7.1 HIGH
v3.1 (cve.org)
EPSS Score
0.43% LOW
0% probability +0.42%
KEV
Not listed
Ransomware
No reports
Public exploits
2 found
Dark Web
Not detected
Timeline
08 Dec 2023, 16:58
Published
Vulnerability first disclosed
25 Aug 2026, 18:02
Last Modified
Vulnerability information updated
Description
An out-of-bounds read vulnerability was found in smb2_dump_detail in fs/smb/client/smb2ops.c in the Linux Kernel. This issue could allow a local attacker to crash the system or leak internal kernel information.
CVSS Metrics
- v3.1•HIGH•Score: 7.1CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
EPSS Trends
Current EPSS score: 0.43%• Percentile: 37%
Techniques & Countermeasures
- CWE-125•Out-of-bounds Read
The product reads data past the end, or before the beginning, of the intended buffer.
Affected Systems
- chainguard•hyperv-daemons-6.18
< 0
- chainguard•hyperv-daemons-generic
< 0
- chainguard•linux-aws-6.12
< 0 | < 6.12.65-r0
- chainguard•linux-aws-6.12-boot-installed
< 0
- chainguard•linux-aws-6.12-fips-boot-installed
< 0
- chainguard•linux-aws-6.12-headers
< 0
- chainguard•linux-aws-6.12-modules
< 0
- chainguard•linux-aws-6.18
< 6.18.10-r0 | < 0
- chainguard•linux-aws-6.18-boot-installed
< 0
- chainguard•linux-aws-6.18-fips-boot-installed
< 0
- chainguard•linux-aws-6.18-headers
< 0
- chainguard•linux-aws-6.18-modules
< 0
- chainguard•linux-aws-generic
< 0 | < 6.18.5-r0
- chainguard•linux-aws-generic-boot-installed
< 0
- chainguard•linux-aws-generic-fips-boot-installed
< 0
- chainguard•linux-aws-generic-headers
< 0
- chainguard•linux-aws-generic-modules
< 0
- chainguard•linux-azure-6.12
< 6.12.65-r1 | < 0
- chainguard•linux-azure-6.18
< 0
- chainguard•linux-azure-6.18-boot-installed
< 0
- chainguard•linux-azure-6.18-fips-boot-installed
< 0
- chainguard•linux-azure-6.18-headers
< 0
- chainguard•linux-azure-6.18-modules
< 0
- chainguard•linux-azure-generic
< 0 | < 6.18.5-r0
- chainguard•linux-azure-generic-boot-installed
< 0
- chainguard•linux-azure-generic-fips-boot-installed
< 0
- chainguard•linux-azure-generic-headers
< 0
- chainguard•linux-azure-generic-modules
< 0
- chainguard•linux-desktop-6.18
all
- chainguard•linux-desktop-6.18-bootc
all
- chainguard•linux-desktop-6.18-bootc-boot-installed
all
- chainguard•linux-desktop-6.18-headers
all
- chainguard•linux-desktop-6.18-modules
all
- chainguard•linux-desktop-7.2
all
- chainguard•linux-desktop-7.2-bootc
all
- chainguard•linux-desktop-7.2-bootc-boot-installed
all
- chainguard•linux-desktop-7.2-headers
all
- chainguard•linux-desktop-7.2-modules
all
- chainguard•linux-firecracker-6.18
all
- chainguard•linux-gcp-6.12
< 0 | < 6.12.65-r0
- chainguard•linux-gcp-6.18
< 6.18.10-r0 | < 0
- chainguard•linux-gcp-6.18-boot-installed
< 0
- chainguard•linux-gcp-6.18-fips-boot-installed
< 0
- chainguard•linux-gcp-6.18-headers
< 0
- chainguard•linux-gcp-6.18-modules
< 0
- chainguard•linux-gcp-generic
< 0 | < 6.18.5-r0
- chainguard•linux-gcp-generic-boot-installed
< 0
- chainguard•linux-gcp-generic-fips-boot-installed
< 0
- chainguard•linux-gcp-generic-headers
< 0
- chainguard•linux-gcp-generic-modules
< 0
Showing first 50 affected entries in server-rendered view.
References (20)
- https://access.redhat.com/errata/RHSA-2024:0723
- https://access.redhat.com/errata/RHSA-2024:0724
- https://access.redhat.com/errata/RHSA-2024:0725
- https://access.redhat.com/errata/RHSA-2024:0881
- https://access.redhat.com/errata/RHSA-2024:0897
- https://access.redhat.com/errata/RHSA-2024:1248
- https://access.redhat.com/errata/RHSA-2024:1404
- https://access.redhat.com/errata/RHSA-2024:2094
- https://access.redhat.com/security/cve/CVE-2023-6610
- https://bugzilla.kernel.org/show_bug.cgi?id=218219
- https://bugzilla.redhat.com/show_bug.cgi?id=2253614
- https://ubuntu.com/security/CVE-2023-6610
- https://ubuntu.com/security/notices/USN-6688-1
- https://ubuntu.com/security/notices/USN-6724-1
- https://www.cve.org/CVERecord?id=CVE-2023-6610
- https://ubuntu.com/security/notices/USN-6724-2
- https://ubuntu.com/security/notices/USN-7123-1
- https://ubuntu.com/security/notices/USN-7194-1
- https://security-tracker.debian.org/tracker/CVE-2023-6610
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=567320c46a60a3c39b69aa1df802d753817a3f86