« List of all CVEs

CVE-2023-4273

Kernel: exfat: stack overflow in exfat_get_uniname_from_ext_entry

Published: 8/9/2023 Last updated: 2/27/2025 Reserved: 8/9/2023

A flaw was found in the exFAT driver of the Linux kernel. The vulnerability exists in the implementation of the file name reconstruction function, which is responsible for reading file name entries from a directory index and merging file name parts belonging to one file into a single long file name. Since the file name characters are copied into a stack variable, a local privileged attacker could use this flaw to overflow the kernel stack.

CNA assigner: redhat (53f830b8-0a3f-465b-8143-3b8a9948e749) Requested by: n/a

Metrics

Version Score Severity Vector String
3.1 6 Medium CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N

Opam packages affected (27)

albatross cdrom conf-bpftool conf-libbpf conf-linux-libc-dev core core_unix hvsock mirage-block-unix mm ocaml-probes orun rawlink rawlink-eio rawlink-lwt shell solo5 solo5-bindings-hvt solo5-bindings-spt solo5-cross-aarch64 solo5-kernel-ukvm tracy-client tuntap uring vhd-format vhd-format-lwt xapi-stdext-unix

Products affected (8)

Product Vendor Version
Red Hat Enterprise Linux 8 Red Hat < 6.2.9200.24216
Red Hat Enterprise Linux 6 Red Hat < 10.0.14393.5850
Red Hat Enterprise Linux 9 Red Hat < 8.7.3.0
Red Hat Enterprise Linux 7 Red Hat n/a
Red Hat Enterprise Linux 9 Red Hat <14.0.0, <13.0.3, <12.0.8
Red Hat Enterprise Linux 9 Red Hat fixed in kernel 6.0-rc4
Red Hat Enterprise Linux 7 Red Hat 1.02
Red Hat Enterprise Linux 8 Red Hat batch number (B/N) 5714442222

References (14)

Credits (1)