Back

MEDIUM

Samba: smb clients can truncate files with read-only permissions

Published Nov 3, 2023

Description

A vulnerability was discovered in Samba, where the flaw allows SMB clients to truncate files, even with read-only permissions when the Samba VFS module "acl_xattr" is configured with "acl_xattr:ignore system acls = yes". The SMB protocol allows opening files when the client requests read-only access but then implicitly truncates the opened file to 0 bytes if the client specifies a separate OVERWRITE create disposition request. The issue arises in configurations that bypass kernel file system permissions checks, relying solely on Samba's permissions.

Affected products

Remediation

Vendor solution

The vulnerability is most commonly associated with the "acl_xattr" module and can be mitigated by setting: ~~~ "acl_xattr:ignore system acls = no" ~~~

Red Hat statement

The vulnerability primarily affects Samba configurations using the "acl_xattr" module with the "acl_xattr:ignore system acls = yes" setting.

Red Hat mitigation

The vulnerability is most commonly associated with the "acl_xattr" module and can be mitigated by setting: ~~~ "acl_xattr:ignore system acls = no" ~~~

Metrics

References (15)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Nov 3, 2023
Updated Nov 20, 2025
Reserved Aug 2, 2023
CISA Vulnrichment
Updated Apr 25, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Oct 10, 2023