Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-4273
HistoryAug 09, 2023 - 12:00 a.m.

CVE-2023-4273

2023-08-0900:00:00
ubuntu.com
ubuntu.com
22
exfat
linux kernel
file name reconstruction
vulnerability
directory index
stack overflow

6.7 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

0.0004 Low

EPSS

Percentile

5.1%

A flaw was found in the exFAT driver of the Linux kernel. The vulnerability
exists in the implementation of the file name reconstruction function,
which is responsible for reading file name entries from a directory index
and merging file name parts belonging to one file into a single long file
name. Since the file name characters are copied into a stack variable, a
local privileged attacker could use this flaw to overflow the kernel stack.

Bugs

OSVersionArchitecturePackageVersionFilename
ubuntu22.04noarchlinux< 5.15.0-86.96UNKNOWN
ubuntu23.04noarchlinux< 6.2.0-34.34UNKNOWN
ubuntu22.04noarchlinux-aws< 5.15.0-1047.52UNKNOWN
ubuntu23.04noarchlinux-aws< 6.2.0-1013.13UNKNOWN
ubuntu20.04noarchlinux-aws-5.15< 5.15.0-1047.52~20.04.1UNKNOWN
ubuntu22.04noarchlinux-aws-6.2< 6.2.0-1013.13~22.04.1UNKNOWN
ubuntu22.04noarchlinux-azure< 5.15.0-1049.56UNKNOWN
ubuntu23.04noarchlinux-azure< 6.2.0-1014.14UNKNOWN
ubuntu20.04noarchlinux-azure-5.15< 5.15.0-1049.56~20.04.1UNKNOWN
ubuntu22.04noarchlinux-azure-6.2< 6.2.0-1014.14~22.04.1UNKNOWN
Rows per page:
1-10 of 461

6.7 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

0.0004 Low

EPSS

Percentile

5.1%