UNIX symbolic link following in Samba - CVE-2022-3592

 

UNIX symbolic link following in Samba - CVE-2022-3592

Published: October 25, 2022


Vulnerability identifier: #VU68700
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-3592
CWE-ID: CWE-61
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to escalate privileges on the system.

The vulnerability exists due to a symlink following issue. A remote user with access to the exported part of the file system under a share via SMB1 unix extensions or NFS can create symlinks to files outside of the smbd configured share path and access otherwise restricted files on the server. 


Affected software

Samba
QVR
QVP (QVR Pro appliances)
QuTS hero
QuTScloud
Gentoo Linux
Amazon Linux AMI
Fedora
HP-UX Common Internet File System (CIFS)
samba
net-fs/samba
QNAP QTS

How to mitigate CVE-2022-3592

Install updates from vendor's website.

Samba - update to 4.17.2
HP-UX Common Internet File System (CIFS) - update to B.04.18.01.00
QuTS hero - update to h5.0.1.2348 build 20230324
samba - addressed in versions 4.16.6-0.fc36, 4.17.2-2.fc37
samba - update to 4.17.5-0
net-fs/samba - update to 4.18.4
QNAP QTS - update to 5.0.1.2346 20230322

External References

Related Security Bulletins