cbcvebase.
CVE-2023-34966
published 2023-07-20

CVE-2023-34966: An infinite loop vulnerability was found in Samba's mdssvc RPC service for Spotlight. When parsing Spotlight mdssvc RPC packets sent by the client, the core…

PriorityP260high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
60.33%
99.0th percentile
An infinite loop vulnerability was found in Samba's mdssvc RPC service for Spotlight. When parsing Spotlight mdssvc RPC packets sent by the client, the core unmarshalling function sl_unpack_loop() did not validate a field in the network packet that contains the count of elements in an array-like structure. By passing 0 as the count value, the attacked function will run in an endless loop consuming 100% CPU. This flaw allows an attacker to issue a malformed RPC request, triggering an infinite loop, resulting in a denial of service condition.

Affected

22 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debiansamba< samba 2:4.17.10+dfsg-0+deb12u1 (bookworm)samba 2:4.17.10+dfsg-0+deb12u1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
redhatenterprise_linux
redhatenterprise_linux
sambasamba< 4.16.114.16.11
sambasamba>= 0 < 2:4.13.13+dfsg-1~deb11u62:4.13.13+dfsg-1~deb11u6
sambasamba>= 0 < 2:4.17.10+dfsg-0+deb12u12:4.17.10+dfsg-0+deb12u1
sambasamba>= 0 < 2:4.18.5+dfsg-12:4.18.5+dfsg-1
sambasamba>= 0 < 2:4.18.5+dfsg-12:4.18.5+dfsg-1
sambasamba>= 0 < 2:4.15.13+dfsg-0ubuntu0.20.04.32:4.15.13+dfsg-0ubuntu0.20.04.3
sambasamba>= 0 < 2:4.15.13+dfsg-0ubuntu1.22:4.15.13+dfsg-0ubuntu1.2
sambasamba>= 0 < 2:4.3.11+dfsg-0ubuntu0.14.04.20+esm132:4.3.11+dfsg-0ubuntu0.14.04.20+esm13
sambasamba>= 0 < 2:4.3.11+dfsg-0ubuntu0.14.04.20+esm142:4.3.11+dfsg-0ubuntu0.14.04.20+esm14
sambasamba>= 0 < 2:4.3.11+dfsg-0ubuntu0.16.04.34+esm22:4.3.11+dfsg-0ubuntu0.16.04.34+esm2
sambasamba>= 0 < 2:4.3.11+dfsg-0ubuntu0.16.04.34+esm32:4.3.11+dfsg-0ubuntu0.16.04.34+esm3
sambasamba>= 0 < 2:4.7.6+dfsg~ubuntu-0ubuntu2.29+esm12:4.7.6+dfsg~ubuntu-0ubuntu2.29+esm1
sambasamba>= 0 < 2:4.7.6+dfsg~ubuntu-0ubuntu2.29+esm22:4.7.6+dfsg~ubuntu-0ubuntu2.29+esm2
sambasamba>= 4.17.0 < 4.17.104.17.10
sambasamba>= 4.18.0 < 4.18.54.18.5

Detection & IOCsextracted from sources · hover to see the quote

  • Target the mdssvc RPC service (Spotlight) in Samba — malformed RPC packets with a count value of 0 in an array-like structure field trigger an infinite loop in sl_unpack_loop(), causing 100% CPU consumption (DoS).
  • Monitor Samba processes for sustained 100% CPU usage on systems where Spotlight is enabled, which may indicate exploitation of this infinite loop vulnerability.
  • ·This vulnerability only affects Samba servers where Spotlight is explicitly enabled. The default configuration has Spotlight disabled. Mitigation is to remove all 'spotlight=yes|true' configuration stanzas.

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.