HomeDefectsLIN1022-3542
Not to be fixed

LIN1022-3542 : Security Advisory - linux - CVE-2023-1194

Created: Mar 6, 2023    Updated: Nov 16, 2023
Resolved Date: Nov 16, 2023
Found In Version: 10.22.33.1
Severity: Standard
Applicable for: Wind River Linux LTS 22
Component/s: Kernel

Description

An out-of-bounds (OOB) memory read flaw was found in parse_lease_state in the KSMBD implementation of the in-kernel samba server and CIFS in the Linux kernel. When an attacker sends the CREATE command with a malformed payload to KSMBD, due to a missing check of `NameOffset` in the `parse_lease_state()` function, the `create_context` object can access invalid memory.

https://nvd.nist.gov/vuln/detail/CVE-2023-1194