Back

HIGH

Use-after-free in parse_lease_state()

Published Nov 3, 2023

Description

An out-of-bounds (OOB) memory read flaw was found in parse_lease_state in the KSMBD implementation of the in-kernel samba server and CIFS in the Linux kernel. When an attacker sends the CREATE command with a malformed payload to KSMBD, due to a missing check of `NameOffset` in the `parse_lease_state()` function, the `create_context` object can access invalid memory.

Affected products

Remediation

Red Hat statement

No shipped kernel version was seen affected by this problem. These files are not built in our source code.

Metrics

References (6)

Change history (4)
  1. MITRE
    • CVSS vector changed from CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H to CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H
    • CVSS score changed from 8.1 to 7.1
  2. REDHAT
    • CVSS vector changed from CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H to CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
    • CVSS score changed from 7.1 to 8.1
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Nov 3, 2023
Updated Feb 13, 2025
Reserved Mar 6, 2023
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Oct 2, 2022