CVE-2023-1194Use After Free in Kernel

Severity
8.1HIGHNVD
EPSS
0.1%
top 84.55%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 3
Latest updateApr 16

Description

An out-of-bounds (OOB) memory read flaw was found in parse_lease_state in the KSMBD implementation of the in-kernel samba server and CIFS in the Linux kernel. When an attacker sends the CREATE command with a malformed payload to KSMBD, due to a missing check of `NameOffset` in the `parse_lease_state()` function, the `create_context` object can access invalid memory.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:HExploitability: 2.8 | Impact: 5.2

Affected Packages5 packages

NVDlinux/linux_kernel5.155.15.145+3
Debianlinux/linux_kernel< 6.1.37-1+2
Ubuntulinux/linux_kernel< 5.15.0-102.112
debiandebian/linux< linux 6.1.37-1 (bookworm)

Also affects: Fedora 37

Patches

🔴Vulnerability Details

4
OSV
linux-aws, linux-aws-5.15 vulnerabilities2024-04-16
OSV
linux, linux-azure, linux-azure-5.15, linux-azure-fde, linux-azure-fde-5.15, linux-gcp, linux-gcp-5.15, linux-gke, linux-gkeop, linux-gkeop-5.15, linux-hwe-5.15, linux-ibm, linux-ibm-5.15, linux-intel2024-04-09
GHSA
GHSA-53pc-8xr3-68wx: An out-of-bounds (OOB) memory read flaw was found in parse_lease_state in the KSMBD implementation of the in-kernel samba server and CIFS in the Linux2023-11-03
OSV
CVE-2023-1194: An out-of-bounds (OOB) memory read flaw was found in parse_lease_state in the KSMBD implementation of the in-kernel samba server and CIFS in the Linux2023-11-03

📋Vendor Advisories

5
Ubuntu
Linux kernel (AWS) vulnerabilities2024-04-16
Ubuntu
Linux kernel vulnerabilities2024-04-09
Microsoft
Use-after-free in parse_lease_state()2023-11-14
Debian
CVE-2023-1194: linux - An out-of-bounds (OOB) memory read flaw was found in parse_lease_state in the KS...2023
Red Hat
kernel: use-after-free in parse_lease_state()2022-10-02
CVE-2023-1194 — Use After Free in Linux Kernel | cvebase