CVE-2023-5568
published 2023-10-25CVE-2023-5568: A heap-based Buffer Overflow flaw was discovered in Samba. It could allow a remote, authenticated attacker to exploit this vulnerability to cause a denial of…
PriorityP333medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
1.57%
72.8th percentile
A heap-based Buffer Overflow flaw was discovered in Samba. It could allow a remote, authenticated attacker to exploit this vulnerability to cause a denial of service.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | samba | < samba 2:4.19.2+dfsg-1 (forky) | samba 2:4.19.2+dfsg-1 (forky) |
| samba | samba | < 4.19.2 | 4.19.2 |
| samba | samba | >= 0 < 2:4.19.2+dfsg-1 | 2:4.19.2+dfsg-1 |
| samba | samba | >= 0 < 2:4.19.2+dfsg-1 | 2:4.19.2+dfsg-1 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv6.5MEDIUM
vendor_redhat7.8HIGH
vendor_debian5.9LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: perf/core: Bail out early if the request AUX area is out of bound
vendor_redhat·2024-05-21·CVSS 7.8
CVE-2023-52835 [HIGH] CWE-125 kernel: perf/core: Bail out early if the request AUX area is out of bound
kernel: perf/core: Bail out early if the request AUX area is out of bound
In the Linux kernel, the following vulnerability has been resolved:
perf/core: Bail out early if the request AUX area is out of bound
When perf-record with a large AUX area, e.g 4GB, it fails with:
#perf record -C 0 -m ,4G -e arm_spe_0// -- sleep 1
failed to mmap with 12 (Cannot allocate memory)
and it reveals a WARNING with __alloc_pages():
------------[ cut here ]------------
WARNING: CPU: 44 PID: 17573 at mm/page_alloc.c:5568 __alloc_pages+0x1ec/0x248
Call trace:
__alloc_pages+0x1ec/0x248
__kmalloc_large_node+0xc0/0x1f8
__kmalloc_node+0x134/0x1e8
rb_alloc_aux+0xe0/0x298
perf_mmap+0x440/0x660
mmap_region+0x308/0x8a8
do_mmap+0x3c0/0x528
vm_mmap_pgoff+0xf4/0x1b8
ksys_mmap_pgoff+0x18c/0x218
__arm64_sys_mmap+0x38/0x58
Red Hat
samba: heap buffer overflow with freshness tokens in the Heimdal KDC
vendor_redhat·2023-10-09·CVSS 5.9
CVE-2023-5568 [MEDIUM] CWE-122 samba: heap buffer overflow with freshness tokens in the Heimdal KDC
samba: heap buffer overflow with freshness tokens in the Heimdal KDC
A heap-based Buffer Overflow flaw was discovered in Samba. It could allow a remote, authenticated attacker to exploit this vulnerability to cause a denial of service.
A heap-based Buffer Overflow flaw was discovered in Samba. It could allow a remote, authenticated attacker to exploit this vulnerability to cause a denial of service.
Statement: Red Hat Enterprise Linux and Fedora do not provide the Heimdal implementation of Kerberos, therefore they are not affected.
Package: samba (Red Hat Enterprise Linux 6) - Not affected
Package: samba (Red Hat Enterprise Linux 7) - Not affected
Package: samba (Red Hat Enterprise Linux 8) - Not affected
Package: samba (Red Hat Enterprise Linux 9) - Not affected
Package: samba (Re
Debian
CVE-2023-5568: samba - A heap-based Buffer Overflow flaw was discovered in Samba. It could allow a remo...
vendor_debian·2023·CVSS 5.9
CVE-2023-5568 [MEDIUM] CVE-2023-5568: samba - A heap-based Buffer Overflow flaw was discovered in Samba. It could allow a remo...
A heap-based Buffer Overflow flaw was discovered in Samba. It could allow a remote, authenticated attacker to exploit this vulnerability to cause a denial of service.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 2:4.19.2+dfsg-1)
sid: resolved (fixed in 2:4.19.2+dfsg-1)
trixie: resolved (fixed in 2:4.19.2+dfsg-1)
GHSA
GHSA-x3c8-vcr7-5m4v: A heap-based Buffer Overflow flaw was discovered in Samba
ghsa_unreviewed·2023-10-25
CVE-2023-5568 [MEDIUM] CWE-122 GHSA-x3c8-vcr7-5m4v: A heap-based Buffer Overflow flaw was discovered in Samba
A heap-based Buffer Overflow flaw was discovered in Samba. It could allow a remote, authenticated attacker to exploit this vulnerability to cause a denial of service.
OSV
CVE-2023-5568: A heap-based Buffer Overflow flaw was discovered in Samba
osv·2023-10-25·CVSS 6.5
CVE-2023-5568 [MEDIUM] CVE-2023-5568: A heap-based Buffer Overflow flaw was discovered in Samba
A heap-based Buffer Overflow flaw was discovered in Samba. It could allow a remote, authenticated attacker to exploit this vulnerability to cause a denial of service.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/security/cve/CVE-2023-5568https://bugzilla.redhat.com/show_bug.cgi?id=2245174https://bugzilla.samba.org/show_bug.cgi?id=15491https://www.samba.org/samba/history/samba-4.19.2.htmlhttps://access.redhat.com/security/cve/CVE-2023-5568https://bugzilla.redhat.com/show_bug.cgi?id=2245174https://bugzilla.samba.org/show_bug.cgi?id=15491https://security.netapp.com/advisory/ntap-20231124-0007/https://www.samba.org/samba/history/samba-4.19.2.html
2023-10-25
Published