Lucene search

K
debiancveDebian Security Bug TrackerDEBIANCVE:CVE-2023-1193
HistoryNov 01, 2023 - 8:15 p.m.

CVE-2023-1193

2023-11-0120:15:08
Debian Security Bug Tracker
security-tracker.debian.org
8
cve-2023-1193
setup async work
use-after-free
ksmbd
samba server
cifs
linux kernel
security issue
unix

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

6.5 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

19.1%

A use-after-free flaw was found in setup_async_work in the KSMBD implementation of the in-kernel samba server and CIFS in the Linux kernel. This issue could allow an attacker to crash the system by accessing freed work.

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

6.5 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

19.1%