Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-4091
HistoryNov 03, 2023 - 8:15 a.m.

Design/Logic Flaw

2023-11-0308:15:00
PRIOn knowledge base
www.prio-n.com
14
samba
vulnerability
file truncation
read-only permissions
smb protocol
vfs module
kernel permissions

6.2 Medium

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

52.0%

A vulnerability was discovered in Samba, where the flaw allows SMB clients to truncate files, even with read-only permissions when the Samba VFS module “acl_xattr” is configured with “acl_xattr:ignore system acls = yes”. The SMB protocol allows opening files when the client requests read-only access but then implicitly truncates the opened file to 0 bytes if the client specifies a separate OVERWRITE create disposition request. The issue arises in configurations that bypass kernel file system permissions checks, relying solely on Samba’s permissions.