Description

A flaw was found within the parsing of extended attributes in the kernel ksmbd module. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this to disclose sensitive information on affected installations of Linux. Only systems with ksmbd enabled are vulnerable to this CVE.

INFO

Published Date :

2024-11-14T12:09:13.182Z

Last Modified :

2024-11-14T19:33:07.493Z

Source :

fedora
AFFECTED PRODUCTS

The following products are affected by CVE-2023-4458 vulnerability.

Vendors Products
Linux
  • Linux Kernel
Redhat
  • Enterprise Linux

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact