CVE-2023-4273

MEDIUM

Linux Kernel exFAT - Buffer Overflow

Title source: llm
STIX 2.1

Description

A flaw was found in the exFAT driver of the Linux kernel. The vulnerability exists in the implementation of the file name reconstruction function, which is responsible for reading file name entries from a directory index and merging file name parts belonging to one file into a single long file name. Since the file name characters are copied into a stack variable, a local privileged attacker could use this flaw to overflow the kernel stack.

Scores

CVSS v3 6.0
EPSS 0.0007
EPSS Percentile 20.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-121 CWE-787
Status published
Products (11)
debian/debian_linux 11.0
debian/debian_linux 12.0
fedoraproject/fedora 37
fedoraproject/fedora 38
linux/linux_kernel 6.5 rc1 (4 CPE variants)
linux/linux_kernel < 6.4
netapp/h300s_firmware
netapp/h410s_firmware
netapp/h500s_firmware
netapp/h700s_firmware
... and 1 more
Published Aug 09, 2023
Tracked Since Feb 18, 2026