Samba: smbd allows client access to unix domain sockets on the file system as root
CVE-2023-3961
Key Information:
- Vendor
- Red Hat
- Status
- Vendor
- CVE Published:
- 3 November 2023
Summary
A vulnerability in Samba has been identified where inadequate sanitization of client pipe names allows for path traversal via Unix directory traversal characters. This flaw may permit attackers to connect SMB clients as root to Unix domain sockets beyond designated private directories. As a result, if a malicious client sends a crafted pipe name that resolves to an external service using an existing Unix domain socket, this could lead to unauthorized service access, potentially resulting in compromise or service disruptions.
Affected Version(s)
Red Hat Enterprise Linux 8 0:4.18.6-2.el8_9
Red Hat Enterprise Linux 8 0:4.18.6-2.el8_9
Red Hat Enterprise Linux 8.6 Extended Update Support 0:4.15.5-13.el8_6
References
EPSS Score
7% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved