CVE-2023-34967: Samba: type confusion in mdssvc rpc service for spotlight
A Type Confusion vulnerability was found in Samba's mdssvc RPC service for Spotlight. When parsing Spotlight mdssvc RPC packets, one encoded data structure is a key-value style dictionary where the keys are character strings, and the values can be any of the supported types in the mdssvc protocol. Due to a lack of type checking in callers of the dallocvalueforkey() function, which returns the object associated with a key, a caller may trigger a crash in tallocgetsize() when talloc detects that the passed-in pointer is not a valid talloc pointer. With an RPC worker process shared among multiple client connections, a malicious client or attacker can trigger a process crash in a shared RPC mdssvc worker process, affecting all other clients this worker serves.
Other sources
Missing type validation in Samba's mdssvc RPC service for Spotlight can be used by an unauthenticated attacker to trigger a process crash in a shared RPC mdssvc worker process.
As RPC worker processes are shared among multiple client connections, a malicious client can crash the worker process affecting all other clients that are also served by this worker.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ubuntu/sambato a version that resolves this vulnerability.Fixed in 2:4.15.13+dfsg-0ubuntu0.20.04.3 - Upgrade
Upgrade
ubuntu/sambato a version that resolves this vulnerability.Fixed in 2:4.15.13+dfsg-0ubuntu1.2 - Upgrade
Upgrade
ubuntu/sambato a version that resolves this vulnerability.Fixed in 2:4.16.8+dfsg-0ubuntu1.2 - Upgrade
Upgrade
ubuntu/sambato a version that resolves this vulnerability.Fixed in 2:4.17.7+dfsg-1ubuntu1.1 - Upgrade
Upgrade
ubuntu/sambato a version that resolves this vulnerability.Fixed in 2:4.18.5+dfsg-1ubuntu1 - Upgrade
Upgrade
debian/sambato a version that resolves this vulnerability.Fixed in 2:4.17.12+dfsg-0+deb12u1Fixed in 2:4.19.3+dfsg-2 - Upgrade
Upgrade
redhat/sambato a version that resolves this vulnerability.Fixed in 4.16.11 - Upgrade
Upgrade
redhat/sambato a version that resolves this vulnerability.Fixed in 4.17.10 - Upgrade
Upgrade
redhat/sambato a version that resolves this vulnerability.Fixed in 4.18.5
Event History
Frequently Asked Questions
What is CVE-2023-34967?
CVE-2023-34967 is a Type Confusion vulnerability found in Samba's mdssvc RPC service for Spotlight.
How severe is CVE-2023-34967?
CVE-2023-34967 has a severity rating of 5.3 (medium).
What software is affected by CVE-2023-34967?
The software affected by CVE-2023-34967 includes Samba versions 2:4.15.13+dfsg-0ubuntu0.20.04.3, 2:4.15.13+dfsg-0ubuntu1.2, 2:4.16.8+dfsg-0ubuntu1.2, 2:4.17.7+dfsg-1ubuntu1.1, 4.16.11, 4.17.10, 4.18.5, and possibly others.
How can I fix CVE-2023-34967?
To fix CVE-2023-34967, it is recommended to update to the patched versions of Samba, such as 2:4.17.10+dfsg-0+deb12u1 or 2:4.19.0+dfsg-1.
Where can I find more information about CVE-2023-34967?
For more information about CVE-2023-34967, you can visit the following references: [Red Hat](https://access.redhat.com/security/cve/CVE-2023-34967), [Samba](https://www.samba.org/samba/security/CVE-2023-34967.html), [Bugzilla](https://bugzilla.redhat.com/show_bug.cgi?id=2222794).