Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-4091
HistoryOct 10, 2023 - 12:00 a.m.

CVE-2023-4091

2023-10-1000:00:00
ubuntu.com
ubuntu.com
21
samba
vulnerability
file truncation
read-only
permissions
smb
protocol
overwrite
samba vfs module
acl_xattr
ignore system acls

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

5.9 Medium

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

52.0%

A vulnerability was discovered in Samba, where the flaw allows SMB clients
to truncate files, even with read-only permissions when the Samba VFS
module “acl_xattr” is configured with “acl_xattr:ignore system acls = yes”.
The SMB protocol allows opening files when the client requests read-only
access but then implicitly truncates the opened file to 0 bytes if the
client specifies a separate OVERWRITE create disposition request. The issue
arises in configurations that bypass kernel file system permissions checks,
relying solely on Samba’s permissions.

Bugs

Notes

Author Note
mdeslaur only vulnerable when using non-default configuraton: acl_xattr:ignore system acls = yes
OSVersionArchitecturePackageVersionFilename
ubuntu18.04noarchsamba< anyUNKNOWN
ubuntu20.04noarchsamba< 2:4.15.13+dfsg-0ubuntu0.20.04.6UNKNOWN
ubuntu22.04noarchsamba< 2:4.15.13+dfsg-0ubuntu1.5UNKNOWN
ubuntu23.04noarchsamba< 2:4.17.7+dfsg-1ubuntu2.3UNKNOWN
ubuntu23.10noarchsamba< 2:4.18.6+dfsg-1ubuntu2.1UNKNOWN
ubuntu24.04noarchsamba< 2:4.18.6+dfsg-1ubuntu2.1UNKNOWN
ubuntu14.04noarchsamba< anyUNKNOWN
ubuntu16.04noarchsamba< anyUNKNOWN

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

5.9 Medium

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

52.0%