← back
CVE-2023-4273

Kernel: exfat: stack overflow in exfat_get_uniname_from_ext_entry

CVSS 6 MEDIUMEPSS 0.7%CWE-121
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6EPSS 0.7%KEV nãoPoC Nuclei Metasploit Patch referenciado
Lifecycle
09 Aug 2023Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A flaw was found in the exFAT driver of the Linux kernel. The vulnerability exists in the implementation of the file name reconstruction function, which is responsible for reading file name entries from a directory index and merging file name parts belonging to one file into a single long file name. Since the file name characters are copied into a stack variable, a local privileged attacker could use this flaw to overflow the kernel stack.
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →