Kernel: ksmbd: smb2_open out-of-bounds read information disclosure vulnerability
Published Nov 14, 2024
7.5
HIGHCVSS 3.1
EPSS 0.84%
Description
A flaw was found within the parsing of extended attributes in the kernel ksmbd module. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this to disclose sensitive information on affected installations of Linux. Only systems with ksmbd enabled are vulnerable to this CVE.
Affected products
No data.
- < 5.15.131
- ≥ 5.16 · < 6.1.52
- ≥ 6.2 · < 6.4.15
- ≥ 6.5 · < 6.5.2
No data.
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
No Red Hat products are affected by this flaw, as the ksmbd code is not included in any shipped RHEL kernel release.
References (5)
- https://access.redhat.com/security/cve/CVE-2023-4458 vdb-entryx_refsource_REDHATVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2325516 issue-trackingx_refsource_REDHATIssue TrackingVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-4458
- https://www.cve.org/CVERecord?id=CVE-2023-4458
- https://www.zerodayinitiative.com/advisories/ZDI-24-590/ Third Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2023-4458 | vdb-entryx_refsource_REDHATVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2325516 | issue-trackingx_refsource_REDHATIssue TrackingVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2023-4458 | ||
| https://www.cve.org/CVERecord?id=CVE-2023-4458 | ||
| https://www.zerodayinitiative.com/advisories/ZDI-24-590/ | Third Party Advisory |
Change history (0)
No recorded changes yet.