Infinite loop in Samba - CVE-2023-34966
Published: July 24, 2023 / Updated: August 28, 2023
Samba
Detailed vulnerability description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to infinite loop when parsing Spotlight mdssvc RPC packets. A remote attacker can consume all available system resources and cause denial of service conditions on servers where Spotlight is explicitly enabled globally or on individual shares with "spotlight = yes".
How to mitigate CVE-2023-34966
Sources
- https://access.redhat.com/security/cve/CVE-2023-34966
- https://www.samba.org/samba/security/CVE-2023-34966
- https://bugzilla.redhat.com/show_bug.cgi?id=2222793
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BPCSGND7LO467AJGR5DYBGZLTCGTOBCC/
- https://www.zerodayinitiative.com/advisories/ZDI-23-1228/