CVE-2023-4130
Description
In the Linux kernel, a flaw was found in the KSMBD server implementation when handling FILE_FULL_EA_INFORMATION requests. The issue arises in the smb2_set_ea() function, where multiple smb2_ea_info buffers are processed using the NextEntryOffset field. KSMBD incorrectly validated the length of the next extended attribute (EA) buffer using the next offset instead of the actual buffer length (buf_len). Since next represents the offset of the current EA rather than the remaining buffer size, this mistake could allow an out-of-bounds access when parsing subsequent entries. This vulnerability could potentially lead to memory corruption or denial of service when processing malicious SMB requests.
Statement
No Red Hat products or offerings are affected by this vulnerability.
Mitigation
No mitigation is currently available that meets Red Hat Product Security’s standards for usability, deployment, applicability, or stability.
Common Vulnerability Scoring System (CVSS) Score Details
Info alert:Important note
CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).
The following CVSS metrics and score provided are preliminary and subject to review.
CVSS v3 Score Breakdown
| Red Hat | NVD | cve.org | |
|---|---|---|---|
| Base Score | 5.5 | 5.5 | 8.1 |
| Attack Vector | Local | Local | Network |
| Attack Complexity | Low | Low | Low |
| Privileges Required | Low | Low | Low |
| User Interaction | None | None | None |
| Scope | Unchanged | Unchanged | Unchanged |
| Confidentiality | None | None | High |
| Integrity Impact | None | None | None |
| Availability Impact | High | High | High |
Vector
Red Hat: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
NVD: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
cve.org: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.