Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2023-1194

Опубликовано: 14 нояб. 2023
Источник: msrc
CVSS3: 8.1
EPSS Низкий

Описание

Use-after-free in parse_lease_state()

EPSS

Процентиль: 26%
0.00087
Низкий

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 7.1
ubuntu
около 2 лет назад

An out-of-bounds (OOB) memory read flaw was found in parse_lease_state in the KSMBD implementation of the in-kernel samba server and CIFS in the Linux kernel. When an attacker sends the CREATE command with a malformed payload to KSMBD, due to a missing check of `NameOffset` in the `parse_lease_state()` function, the `create_context` object can access invalid memory.

CVSS3: 8.1
redhat
около 3 лет назад

An out-of-bounds (OOB) memory read flaw was found in parse_lease_state in the KSMBD implementation of the in-kernel samba server and CIFS in the Linux kernel. When an attacker sends the CREATE command with a malformed payload to KSMBD, due to a missing check of `NameOffset` in the `parse_lease_state()` function, the `create_context` object can access invalid memory.

CVSS3: 7.1
nvd
около 2 лет назад

An out-of-bounds (OOB) memory read flaw was found in parse_lease_state in the KSMBD implementation of the in-kernel samba server and CIFS in the Linux kernel. When an attacker sends the CREATE command with a malformed payload to KSMBD, due to a missing check of `NameOffset` in the `parse_lease_state()` function, the `create_context` object can access invalid memory.

CVSS3: 7.1
debian
около 2 лет назад

An out-of-bounds (OOB) memory read flaw was found in parse_lease_state ...

CVSS3: 7.1
github
около 2 лет назад

An out-of-bounds (OOB) memory read flaw was found in parse_lease_state in the KSMBD implementation of the in-kernel samba server and CIFS in the Linux kernel. When an attacker sends the CREATE command with a malformed payload to KSMBD, due to a missing check of `NameOffset` in the `parse_lease_state()` function, the `create_context` object can access invalid memory.

EPSS

Процентиль: 26%
0.00087
Низкий

8.1 High

CVSS3