Logo
vulnerabilityCVE-2023-4091
Name
CVE-2023-4091
Source
NVD ( link)Debian ( link)
Description
A vulnerability was discovered in Samba, where the flaw allows SMB clients to truncate files, even with read-only permissions when the Samba VFS module "acl_xattr" is configured with "acl_xattr:ignore system acls = yes". The SMB protocol allows opening files when the client requests read-only access but then implicitly truncates the opened file to 0 bytes if the client specifies a separate OVERWRITE create disposition request. The issue arises in configurations that bypass kernel file system permissions checks, relying solely on Samba's permissions.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
samba
Patched

Vulnerability Ratings#


6.5
CVSSv31
6.5
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
4.22.10
Not Affected
buildroot
master
4.24.3
Not Affected
openwrt
master
4.22.7-r3
Not Affected
openwrt
openwrt-25.12
4.22.7-r3
Not Affected
yocto
master
4.23.5
Not Affected
yocto
scarthgap
4.19.9
Not Affected

Resolved with patches#


samba (yocto:kirkstone)

#
Title
Author
Resolve
1
CVE-2023-4091: smbd: use open_access_mask for access check in
Ralph Boehme <slow@samba.org>
CVE-2023-4091
2
CVE-2023-4091: smbtorture: test overwrite dispositions on
Ralph Boehme <slow@samba.org>
CVE-2023-4091