6.7

CVE-2023-4273

Exploit

Kernel: exfat: stack overflow in exfat_get_uniname_from_ext_entry

A flaw was found in the exFAT driver of the Linux kernel. The vulnerability exists in the implementation of the file name reconstruction function, which is responsible for reading file name entries from a directory index and merging file name parts belonging to one file into a single long file name. Since the file name characters are copied into a stack variable, a local privileged attacker could use this flaw to overflow the kernel stack.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version < 6.4
Linux ≫ Linux Kernel Version 6.5 Update rc1
Linux ≫ Linux Kernel Version 6.5 Update rc2
Linux ≫ Linux Kernel Version 6.5 Update rc3
Linux ≫ Linux Kernel Version 6.5 Update rc4
Fedoraproject ≫ Fedora Version 37
Fedoraproject ≫ Fedora Version 38
Redhat ≫ Enterprise Linux Version 9.0
Debian ≫ Debian Linux Version 11.0
Debian ≫ Debian Linux Version 12.0
Netapp ≫ H300s Firmware Version -
   Netapp ≫ H300s Version -
Netapp ≫ H500s Firmware Version -
   Netapp ≫ H500s Version -
Netapp ≫ H700s Firmware Version -
   Netapp ≫ H700s Version -
Netapp ≫ H410s Firmware Version -
   Netapp ≫ H410s Version -
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.65% 0.479
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.7 0.8 5.9
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
RedHat 6 0.8 5.2
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
CWE-121 Stack-based Buffer Overflow

A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).

CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

https://lists.debian.org/debian-lts-announce/2023/10/msg00027.html
https://www.debian.org/security/2023/dsa-5480
https://www.debian.org/security/2023/dsa-5492
https://access.redhat.com/errata/RHSA-2023:6583
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/344H6HO6SSC4KT7PDFXSDIXKMKHISSGF/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3TYLSJ2SAI7RF56ZLQ5CQWCJLVJSD73Q/
https://security.netapp.com/advisory/ntap-20231027-0002/
https://access.redhat.com/security/cve/CVE-2023-4273
Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2221609
Patch
Third Party Advisory
Issue Tracking
https://dfir.ru/2023/08/23/cve-2023-4273-a-vulnerability-in-the-linux-exfat-driver/
Third Party Advisory
Exploit