← Back to browse · API

CVE-2023-34967

Severity
MEDIUM
CVSS
5.3
EPSS
0.60938
Risk score
42.53
CISA KEV
No
PoC
No
Published
2023-07-20
Modified
2025-11-20
First seen
2026-08-07
Aliases
EUVD-2023-39006, GHSA-86P4-VHR6-2VV3
Products
Red Hat:Red Hat Enterprise Linux 8 patch: 0:4.18.6-1.el8, Red Hat:Red Hat Enterprise Linux 8.6 Extended Update Support patch: 0:4.15.5-15.el8_6, Red Hat:Red Hat Enterprise Linux 8.8 Extended Update Support patch: 0:4.17.5-5.el8_8, Red Hat:Red Hat Enterprise Linux 9 patch: 0:4.18.6-100.el9, Red Hat:Red Hat Virtualization 4 for Red Hat Enterprise Linux 8 patch: 0:4.15.5-15.el8_6
Sources
euvd EUVD-2023-39006

Description

A Type Confusion vulnerability was found in Samba's mdssvc RPC service for Spotlight. When parsing Spotlight mdssvc RPC packets, one encoded data structure is a key-value style dictionary where the keys are character strings, and the values can be any of the supported types in the mdssvc protocol. Due to a lack of type checking in callers of the dalloc_value_for_key() function, which returns the object associated with a key, a caller may trigger a crash in talloc_get_size() when talloc detects that the passed-in pointer is not a valid talloc pointer. With an RPC worker process shared among multiple client connections, a malicious client or attacker can trigger a process crash in a shared RPC mdssvc worker process, affecting all other clients this worker serves.

References