CVE-2023-4130

Description

In the Linux kernel, a flaw was found in the KSMBD server implementation when handling FILE_FULL_EA_INFORMATION requests. The issue arises in the smb2_set_ea() function, where multiple smb2_ea_info buffers are processed using the NextEntryOffset field. KSMBD incorrectly validated the length of the next extended attribute (EA) buffer using the next offset instead of the actual buffer length (buf_len). Since next represents the offset of the current EA rather than the remaining buffer size, this mistake could allow an out-of-bounds access when parsing subsequent entries. This vulnerability could potentially lead to memory corruption or denial of service when processing malicious SMB requests.

Statement

No Red Hat products or offerings are affected by this vulnerability.

Mitigation

No mitigation is currently available that meets Red Hat Product Security’s standards for usability, deployment, applicability, or stability.

Common Vulnerability Scoring System (CVSS) Score Details

Info alert:Important note

CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).

The following CVSS metrics and score provided are preliminary and subject to review.

CVSS v3 Score Breakdown

Red HatNVDcve.org
Base Score5.55.58.1
Attack VectorLocalLocalNetwork
Attack ComplexityLowLowLow
Privileges RequiredLowLowLow
User InteractionNoneNoneNone
ScopeUnchangedUnchangedUnchanged
ConfidentialityNoneNoneHigh
Integrity ImpactNoneNoneNone
Availability ImpactHighHighHigh

Vector

Red Hat: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

NVD: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

cve.org: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

Frequently Asked Questions

Want to get errata notifications? Sign up here.