PT-2023-9354 · Linux+2 · Linux Kernel+2

Published

2023-11-07

·

Updated

2024-09-27

·

CVE-2023-52755

CVSS v3.1

8.4

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux Kernel (affected versions not specified)
Description The issue is related to a slab out-of-bounds write in the smb inherit dacl() function, caused by offsets being larger than the pntsd allocation size. This can lead to unauthorized access to confidential data, disruption of data integrity, and denial of service. The patch adds a check to validate 3 offsets using the allocation size.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Weakness Enumeration

Related Identifiers

AZL-47639
AZL-47691
BDU:2024-06909
CVE-2023-52755
OESA-2024-1860
OESA-2024-1861
ZDI-24-996

Affected Products

Astra Linux
Linux Kernel
Red Os