Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-1193
HistoryNov 01, 2023 - 12:00 a.m.

CVE-2023-1193

2023-11-0100:00:00
ubuntu.com
ubuntu.com
15
use-after-free flaw
ksmbd
samba server
cifs
linux kernel
crash vulnerability
bugzilla
sbeattie
config option

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

6.4 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

19.1%

A use-after-free flaw was found in setup_async_work in the KSMBD
implementation of the in-kernel samba server and CIFS in the Linux kernel.
This issue could allow an attacker to crash the system by accessing freed
work.

Bugs

Notes

Author Note
sbeattie this affects the KSMBD subsystem, which generally should not be used, userspace samba is the safer choice. marking the introduction of the cifsd/ksmbd config option as the break commit

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

6.4 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

19.1%