HomeDefectsLIN1021-6251
Fixed

LIN1021-6251 : Security Advisory - linux - CVE-2023-4273

Created: Aug 10, 2023    Updated: Sep 15, 2024
Resolved Date: Aug 20, 2023
Found In Version: 10.21.20.1
Fix Version: 10.21.20.20
Severity: Standard
Applicable for: Wind River Linux LTS 21
Component/s: Kernel

Description

A flaw was found in the exFAT driver of the Linux kernel. The vulnerability exists in the implementation of the file name reconstruction function, which is responsible for reading file name entries from a directory index and merging file name parts belonging to one file into a single long file name. Since the file name characters are copied into a stack variable, a local privileged attacker could use this flaw to overflow the kernel stack.

CREATE(Triage):(User=admin) CVE-2023-4273 (https://nvd.nist.gov/vuln/detail/CVE-2023-4273)

CVEs