PT-2021-7964 · Intel+3 · Intel(R) Ssd Tools+3

Published

2021-12-03

·

Updated

2023-10-05

·

CVE-2023-28736

CVSS v3.1

6.7

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Intel(R) SSD Tools versions prior to mdadm-4.2-rc2
Description The issue is related to a buffer overflow in the Intel(R) SSD Tools software, specifically in the mdadm utility, which is used for managing RAID arrays. This buffer overflow is caused by the lack of input validation, allowing a potential escalation of privilege via local access. An attacker could exploit this issue to gain access to confidential data, compromise data integrity, and cause a denial of service.
Recommendations For versions prior to mdadm-4.2-rc2, update to version mdadm-4.2-rc2 or later to resolve the issue. As a temporary workaround, consider restricting local access to the system to minimize the risk of exploitation. Additionally, restrict the use of the mdadm utility until the update is applied.

Fix

Buffer Overflow

Weakness Enumeration

Related Identifiers

AZL-27938
AZL-34974
BDU:2023-07668
CVE-2023-28736
OESA-2023-1649
OPENSUSE-SU-2023_3953-1
SUSE-SU-2023:3691-1
SUSE-SU-2023:3953-1
SUSE-SU-2023_3691-1
SUSE-SU-2023_3953-1

Affected Products

Astra Linux
Debian
Intel(R) Ssd Tools
Suse