Logo
vulnerabilityCVE-2023-34966
Name
CVE-2023-34966
Source
NVD ( link)Debian ( link)
Description
An infinite loop vulnerability was found in Samba's mdssvc RPC service for Spotlight. When parsing Spotlight mdssvc RPC packets sent by the client, the core unmarshalling function sl_unpack_loop() did not validate a field in the network packet that contains the count of elements in an array-like structure. By passing 0 as the count value, the attacked function will run in an endless loop consuming 100% CPU. This flaw allows an attacker to issue a malformed RPC request, triggering an infinite loop, resulting in a denial of service condition.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
samba
Patched

Vulnerability Ratings#


7.5
CVSSv31
7.5
CVSSv31

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
4.22.10
Not Affected
buildroot
master
4.24.3
Not Affected
openwrt
master
4.22.7-r3
Not Affected
openwrt
openwrt-25.12
4.22.7-r3
Not Affected
yocto
master
4.23.5
Not Affected
yocto
scarthgap
4.19.9
Not Affected

Resolved with patches#


samba (yocto:kirkstone)

#
Title
Author
Resolve
1
CVE-2023-34966: CI: test for sl_unpack_loop()
Ralph Boehme <slow@samba.org>
CVE-2023-34966
2
CVE-2023-34966: mdssvc: harden sl_unpack_loop()
Ralph Boehme <slow@samba.org>
CVE-2023-34966