6.7
CVE-2023-4273
- EPSS 0.65%
- Veröffentlicht 09.08.2023 15:15:09
- Zuletzt bearbeitet 21.11.2024 08:34:46
- Erkennungen
Kernel: exfat: stack overflow in exfat_get_uniname_from_ext_entry
A flaw was found in the exFAT driver of the Linux kernel. The vulnerability exists in the implementation of the file name reconstruction function, which is responsible for reading file name entries from a directory index and merging file name parts belonging to one file into a single long file name. Since the file name characters are copied into a stack variable, a local privileged attacker could use this flaw to overflow the kernel stack.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version < 6.4
Linux ≫ Linux Kernel Version 6.5 Update rc1
Linux ≫ Linux Kernel Version 6.5 Update rc2
Linux ≫ Linux Kernel Version 6.5 Update rc3
Linux ≫ Linux Kernel Version 6.5 Update rc4
Fedoraproject ≫ Fedora Version 37
Fedoraproject ≫ Fedora Version 38
Redhat ≫ Enterprise Linux Version 9.0
Debian ≫ Debian Linux Version 11.0
Debian ≫ Debian Linux Version 12.0
Netapp ≫ H300s Firmware Version -
Netapp ≫ H500s Firmware Version -
Netapp ≫ H700s Firmware Version -
Netapp ≫ H410s Firmware Version -
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.65% | 0.479 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 6.7 | 0.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|
| RedHat | 6 | 0.8 | 5.2 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
|
CWE-121 Stack-based Buffer Overflow
A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).
CWE-787 Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
https://lists.debian.org/debian-lts-announce/2023/10/msg00027.html
https://www.debian.org/security/2023/dsa-5480
https://www.debian.org/security/2023/dsa-5492
https://access.redhat.com/errata/RHSA-2023:6583
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/344H6HO6SSC4KT7PDFXSDIXKMKHISSGF/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3TYLSJ2SAI7RF56ZLQ5CQWCJLVJSD73Q/
https://security.netapp.com/advisory/ntap-20231027-0002/
https://access.redhat.com/security/cve/CVE-2023-4273
https://bugzilla.redhat.com/show_bug.cgi?id=2221609
https://dfir.ru/2023/08/23/cve-2023-4273-a-vulnerability-in-the-linux-exfat-driver/