Wind River Support Network

HomeDefectsLIN1018-11039
Fixed

LIN1018-11039 : Security Advisory - linux - CVE-2023-4273

Created: Aug 9, 2023    Updated: Aug 31, 2023
Resolved Date: Aug 31, 2023
Found In Version: 10.18.44.1
Severity: Standard
Applicable for: Wind River Linux LTS 18
Component/s: Kernel

Description

A flaw was found in the exFAT driver of the Linux kernel. The vulnerability exists in the implementation of the file name reconstruction function, which is responsible for reading file name entries from a directory index and merging file name parts belonging to one file into a single long file name. Since the file name characters are copied into a stack variable, a local privileged attacker could use this flaw to overflow the kernel stack.

CREATE(Triage):(User=admin) CVE-2023-4273 (https://nvd.nist.gov/vuln/detail/CVE-2023-4273)
Live chat
Online