PT-2023-31158 · Unknown+3 · Gnu Core Utilities+3
Moviuro
·
Published
2023-11-24
·
Updated
2025-04-05
·
CVE-2023-49298
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
OpenZFS versions 2.1.13 and earlier
OpenZFS versions 2.2.x through 2.2.1
Description
The issue is related to the replacement of file contents with zero-valued bytes, potentially disabling security mechanisms in certain scenarios involving applications that rely on efficient copying of file data. This can occur when using applications like
cp from recent GNU Core Utilities (coreutils) versions to preserve rule sets for denying unauthorized access, such as when configuring access control with the /etc/hosts.deny file. The issue is not always security-related but can be in realistic situations.Recommendations
For OpenZFS versions 2.1.13 and earlier, consider updating to a version where this issue is fixed, if available.
For OpenZFS versions 2.2.x through 2.2.1, consider updating to a version where this issue is fixed, if available.
As a temporary workaround, consider avoiding the use of applications that rely on efficient copying of file data, such as
cp, when preserving security-related configurations until a patch is available.
Restrict access to sensitive files and configurations to minimize the risk of exploitation.Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Gnu Core Utilities
Openzfs
Red Os