Samba: smbd allows client access to unix domain sockets on the file system as root
CVE-2023-3961
9.1CRITICAL
Key Information:
- Vendor
- Red Hat
- Status
- Vendor
- CVE Published:
- 3 November 2023
Summary
A vulnerability in Samba has been identified where inadequate sanitization of client pipe names allows for path traversal via Unix directory traversal characters. This flaw may permit attackers to connect SMB clients as root to Unix domain sockets beyond designated private directories. As a result, if a malicious client sends a crafted pipe name that resolves to an external service using an existing Unix domain socket, this could lead to unauthorized service access, potentially resulting in compromise or service disruptions.
Affected Version(s)
Red Hat Enterprise Linux 8 0:4.18.6-2.el8_9
Red Hat Enterprise Linux 8 0:4.18.6-2.el8_9
Red Hat Enterprise Linux 8.6 Extended Update Support 0:4.15.5-13.el8_6
References
CVSS V3.1
Score:
9.1
Severity:
CRITICAL
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Collectors
NVD DatabaseMitre Database