PT-2021-7964 · Intel+3 · Intel(R) Ssd Tools+3
Published
2021-12-03
·
Updated
2023-10-05
·
CVE-2023-28736
CVSS v3.1
6.7
Medium
| Vector | AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Intel(R) SSD Tools versions prior to mdadm-4.2-rc2
Description
The issue is related to a buffer overflow in the Intel(R) SSD Tools software, specifically in the mdadm utility, which is used for managing RAID arrays. This buffer overflow is caused by the lack of input validation, allowing a potential escalation of privilege via local access. An attacker could exploit this issue to gain access to confidential data, compromise data integrity, and cause a denial of service.
Recommendations
For versions prior to mdadm-4.2-rc2, update to version mdadm-4.2-rc2 or later to resolve the issue. As a temporary workaround, consider restricting local access to the system to minimize the risk of exploitation. Additionally, restrict the use of the mdadm utility until the update is applied.
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Debian
Intel(R) Ssd Tools
Suse