---
id: CVE-2023-4130
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  ksmbd: fix wrong next length validation of ea buffer in smb2_set_ea()

  There are multiple smb2_ea_info buffers in FILE_FULL_EA_INFORMATION request
  from client
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  ksmbd: fix wrong next length validation of ea buffer in smb2_set_ea()

  There are multiple smb2_ea_info buffers in FILE_FULL_EA_INFORMATION request
  from client. ksmbd fi…
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H'
vendor: linux
product: linux_kernel
affected:
  - 'linux_kernel >= 5.15, < 5.15.127'
  - 'linux_kernel >= 5.16, < 6.1.46'
  - 'linux_kernel >= 6.2, < 6.4.11'
  - linux_kernel = 6.5
patched:
  - linux_kernel 6.4.11
published: '2025-08-16'
updated: '2026-08-15'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2023-4130'
references:
  - url: 'https://git.kernel.org/stable/c/4bf629262f9118ee91b1c3a518ebf2b3bcb22180'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/79ed288cef201f1f212dfb934bcaac75572fb8f6'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/aeb974907642be095e38ecb1a400ca583958b2b0'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/f339d76a3a972601d0738b881b099d49ebbdc3a2'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
epss: 0.00493
epssPercentile: 0.41444
ingestedAt: '2026-08-15T13:26:45.347Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

ksmbd: fix wrong next length validation of ea buffer in smb2_set_ea()

There are multiple smb2_ea_info buffers in FILE_FULL_EA_INFORMATION request
from client. ksmbd find next smb2_ea_info using ->NextEntryOffset of
current smb2_ea_info. ksmbd need to validate buffer length Before
accessing the next ea. ksmbd should check buffer length using buf_len,
not next variable. next is the start offset of current ea that got from
previous ea.

## Affected

- `linux_kernel >= 5.15, < 5.15.127`
- `linux_kernel >= 5.16, < 6.1.46`
- `linux_kernel >= 6.2, < 6.4.11`
- `linux_kernel = 6.5`

## Remediation

Upgrade past the affected range:

- `linux_kernel 6.4.11`
