CVE-2023-34966: Samba: infinite loop in mdssvc rpc service for spotlight
An infinite loop vulnerability was found in Samba's mdssvc RPC service for Spotlight. When parsing Spotlight mdssvc RPC packets sent by the client, the core unmarshalling function slunpackloop() did not validate a field in the network packet that contains the count of elements in an array-like structure. By passing 0 as the count value, the attacked function will run in an endless loop consuming 100% CPU. This flaw allows an attacker to issue a malformed RPC request, triggering an infinite loop, resulting in a denial of service condition.
Other sources
When parsing Spotlight mdssvc RPC packets sent by the client, the core unmarshalling function slunpackloop() did not validate a field in the network packet that contains the count of elements in an array-like structure. By passing 0 as the count value, the attacked function will run in an endless loop consuming 100% CPU. This infinite loop bug in Samba's mdssvc RPC service for Spotlight can be triggered by an unauthenticated attacker by issuing a malformed RPC request.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ubuntu/sambato a version that resolves this vulnerability.Fixed in 2:4.15.13+dfsg-0ubuntu0.20.04.3 - Upgrade
Upgrade
ubuntu/sambato a version that resolves this vulnerability.Fixed in 2:4.15.13+dfsg-0ubuntu1.2 - Upgrade
Upgrade
ubuntu/sambato a version that resolves this vulnerability.Fixed in 2:4.16.8+dfsg-0ubuntu1.2 - Upgrade
Upgrade
ubuntu/sambato a version that resolves this vulnerability.Fixed in 2:4.17.7+dfsg-1ubuntu1.1 - Upgrade
Upgrade
ubuntu/sambato a version that resolves this vulnerability.Fixed in 2:4.18.5+dfsg-1ubuntu1 - Upgrade
Upgrade
debian/sambato a version that resolves this vulnerability.Fixed in 2:4.17.12+dfsg-0+deb12u1Fixed in 2:4.19.3+dfsg-2 - Upgrade
Upgrade
redhat/sambato a version that resolves this vulnerability.Fixed in 4.16.11 - Upgrade
Upgrade
redhat/sambato a version that resolves this vulnerability.Fixed in 4.17.10 - Upgrade
Upgrade
redhat/sambato a version that resolves this vulnerability.Fixed in 4.18.5 - Configuration
As a workaround, disable Spotlight by removing all Samba configuration stanzas that enable Spotlight ("spotlight=yes"|"spotlight=true"), so Spotlight-related mdssvc RPC functionality is not available.
Samba mdssvc RPC service (Spotlight) spotlight = remove all configuration stanzas that enable Spotlight (e.g., "spotlight=yes" or "spotlight=true")
Event History
Frequently Asked Questions
What is CVE-2023-34966?
CVE-2023-34966 is an infinite loop vulnerability found in Samba's mdssvc RPC service for Spotlight.
How severe is CVE-2023-34966?
CVE-2023-34966 has a severity level of high.
What software is affected by CVE-2023-34966?
Samba versions up to and including 4.18.5 are affected by CVE-2023-34966.
How can I fix CVE-2023-34966?
To fix CVE-2023-34966, update your Samba software to version 4.18.6 or higher.
Where can I find more information about CVE-2023-34966?
You can find more information about CVE-2023-34966 on the Red Hat Security Advisory, Samba website, and Bugzilla.