Unrated severityNVD Advisory· Published Jul 20, 2023· Updated Nov 20, 2025
Samba: spotlight server-side share path disclosure
CVE-2023-34968
Description
A path disclosure vulnerability was found in Samba. As part of the Spotlight protocol, Samba discloses the server-side absolute path of shares, files, and directories in the results for search queries. This flaw allows a malicious client or an attacker with a targeted RPC request to view the information that is part of the disclosed path.
Affected products
67- Red Hat/Red Hat Enterprise Linux 8v5cpe:/a:redhat:enterprise_linux:8::crbRange: 0:4.18.6-1.el8
- Red Hat/Red Hat Enterprise Linux 8.8 Extended Update Supportv5cpe:/a:redhat:rhel_eus:8.8::appstreamRange: 0:4.17.5-5.el8_8
- Red Hat/Red Hat Storage 3v5cpe:/a:redhat:storage:3
- Red Hat/Red Hat Enterprise Linux 6v5cpe:/o:redhat:enterprise_linux:6
- Red Hat/Red Hat Enterprise Linux 7v5cpe:/o:redhat:enterprise_linux:7
- Red Hat/Red Hat Enterprise Linux 9v5cpe:/o:redhat:enterprise_linux:9::baseosRange: 0:4.18.6-100.el9
- Red Hat/Red Hat Virtualization 4 for Red Hat Enterprise Linux 8v5cpe:/o:redhat:rhel_eus:8.6::baseosRange: 0:4.15.5-15.el8_6
- osv-coords60 versionspkg:rpm/almalinux/ctdbpkg:rpm/almalinux/libnetapipkg:rpm/almalinux/libnetapi-develpkg:rpm/almalinux/libsmbclientpkg:rpm/almalinux/libsmbclient-develpkg:rpm/almalinux/libwbclientpkg:rpm/almalinux/libwbclient-develpkg:rpm/almalinux/python3-sambapkg:rpm/almalinux/python3-samba-dcpkg:rpm/almalinux/python3-samba-develpkg:rpm/almalinux/python3-samba-testpkg:rpm/almalinux/sambapkg:rpm/almalinux/samba-clientpkg:rpm/almalinux/samba-client-libspkg:rpm/almalinux/samba-commonpkg:rpm/almalinux/samba-common-libspkg:rpm/almalinux/samba-common-toolspkg:rpm/almalinux/samba-dcerpcpkg:rpm/almalinux/samba-dc-libspkg:rpm/almalinux/samba-develpkg:rpm/almalinux/samba-krb5-printingpkg:rpm/almalinux/samba-ldb-ldap-modulespkg:rpm/almalinux/samba-libspkg:rpm/almalinux/samba-pidlpkg:rpm/almalinux/samba-testpkg:rpm/almalinux/samba-test-libspkg:rpm/almalinux/samba-toolspkg:rpm/almalinux/samba-usersharespkg:rpm/almalinux/samba-vfs-iouringpkg:rpm/almalinux/samba-winbindpkg:rpm/almalinux/samba-winbind-clientspkg:rpm/almalinux/samba-winbind-krb5-locatorpkg:rpm/almalinux/samba-winbind-modulespkg:rpm/almalinux/samba-winexepkg:rpm/opensuse/samba&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/samba&distro=openSUSE%20Leap%2015.5pkg:rpm/opensuse/samba&distro=openSUSE%20Leap%20Micro%205.3pkg:rpm/opensuse/samba&distro=openSUSE%20Leap%20Micro%205.4pkg:rpm/opensuse/samba&distro=openSUSE%20Tumbleweedpkg:rpm/suse/samba&distro=SUSE%20Enterprise%20Storage%207pkg:rpm/suse/samba&distro=SUSE%20Enterprise%20Storage%207.1pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2012%20SP5pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2015%20SP3pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2015%20SP4pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2015%20SP5pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP3-ESPOSpkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP3-LTSSpkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Micro%205.2pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Micro%205.3pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Micro%205.4pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP4pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP5pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Real%20Time%2015%20SP3pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP3-LTSSpkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP3pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5pkg:rpm/suse/samba&distro=SUSE%20Manager%20Proxy%204.2pkg:rpm/suse/samba&distro=SUSE%20Manager%20Server%204.2
< 4.18.6-100.el9+ 59 more
- (no CPE)range: < 4.18.6-100.el9
- (no CPE)range: < 4.18.6-100.el9
- (no CPE)range: < 4.18.6-100.el9
- (no CPE)range: < 4.18.6-100.el9
- (no CPE)range: < 4.18.6-100.el9
- (no CPE)range: < 4.18.6-100.el9
- (no CPE)range: < 4.18.6-100.el9
- (no CPE)range: < 4.18.6-100.el9
- (no CPE)range: < 4.18.6-100.el9
- (no CPE)range: < 4.18.6-100.el9
- (no CPE)range: < 4.18.6-100.el9
- (no CPE)range: < 4.18.6-100.el9
- (no CPE)range: < 4.18.6-100.el9
- (no CPE)range: < 4.18.6-100.el9
- (no CPE)range: < 4.18.6-100.el9
- (no CPE)range: < 4.18.6-100.el9
- (no CPE)range: < 4.18.6-100.el9
- (no CPE)range: < 4.18.6-100.el9
- (no CPE)range: < 4.18.6-100.el9
- (no CPE)range: < 4.18.6-100.el9
- (no CPE)range: < 4.18.6-100.el9
- (no CPE)range: < 4.18.6-100.el9
- (no CPE)range: < 4.18.6-100.el9
- (no CPE)range: < 4.18.6-100.el9
- (no CPE)range: < 4.18.6-100.el9
- (no CPE)range: < 4.18.6-100.el9
- (no CPE)range: < 4.18.6-100.el9
- (no CPE)range: < 4.18.6-100.el9
- (no CPE)range: < 4.18.6-100.el9
- (no CPE)range: < 4.18.6-100.el9
- (no CPE)range: < 4.18.6-100.el9
- (no CPE)range: < 4.18.6-100.el9
- (no CPE)range: < 4.18.6-100.el9
- (no CPE)range: < 4.18.6-100.el9
- (no CPE)range: < 4.15.13+git.663.9c654e06cdb-150400.3.28.1
- (no CPE)range: < 4.17.9+git.367.dae41ffdd1f-150500.3.5.1
- (no CPE)range: < 4.15.13+git.663.9c654e06cdb-150400.3.28.1
- (no CPE)range: < 4.15.13+git.663.9c654e06cdb-150400.3.28.1
- (no CPE)range: < 4.18.5+git.313.c8e274c7852-1.1
- (no CPE)range: < 4.13.13+git.643.8caa136952b-150200.3.26.3
- (no CPE)range: < 4.15.13+git.663.9c654e06cdb-150300.3.57.5
- (no CPE)range: < 4.15.13+git.621.c8ae836ff82-3.85.1
- (no CPE)range: < 4.15.13+git.663.9c654e06cdb-150300.3.57.5
- (no CPE)range: < 4.15.13+git.663.9c654e06cdb-150400.3.28.1
- (no CPE)range: < 4.17.9+git.367.dae41ffdd1f-150500.3.5.1
- (no CPE)range: < 4.15.13+git.663.9c654e06cdb-150300.3.57.5
- (no CPE)range: < 4.15.13+git.663.9c654e06cdb-150300.3.57.5
- (no CPE)range: < 4.15.13+git.663.9c654e06cdb-150300.3.57.5
- (no CPE)range: < 4.15.13+git.663.9c654e06cdb-150400.3.28.1
- (no CPE)range: < 4.15.13+git.663.9c654e06cdb-150400.3.28.1
- (no CPE)range: < 4.15.13+git.663.9c654e06cdb-150400.3.28.1
- (no CPE)range: < 4.17.9+git.367.dae41ffdd1f-150500.3.5.1
- (no CPE)range: < 4.15.13+git.663.9c654e06cdb-150300.3.57.5
- (no CPE)range: < 4.15.13+git.621.c8ae836ff82-3.85.1
- (no CPE)range: < 4.15.13+git.663.9c654e06cdb-150300.3.57.5
- (no CPE)range: < 4.15.13+git.621.c8ae836ff82-3.85.1
- (no CPE)range: < 4.15.13+git.663.9c654e06cdb-150300.3.57.5
- (no CPE)range: < 4.15.13+git.621.c8ae836ff82-3.85.1
- (no CPE)range: < 4.15.13+git.663.9c654e06cdb-150300.3.57.5
- (no CPE)range: < 4.15.13+git.663.9c654e06cdb-150300.3.57.5
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- access.redhat.com/errata/RHSA-2023:6667mitrevendor-advisoryx_refsource_REDHAT
- access.redhat.com/errata/RHSA-2023:7139mitrevendor-advisoryx_refsource_REDHAT
- access.redhat.com/errata/RHSA-2024:0423mitrevendor-advisoryx_refsource_REDHAT
- access.redhat.com/errata/RHSA-2024:0580mitrevendor-advisoryx_refsource_REDHAT
- access.redhat.com/security/cve/CVE-2023-34968mitrevdb-entryx_refsource_REDHAT
- bugzilla.redhat.com/show_bug.cgimitreissue-trackingx_refsource_REDHAT
- www.samba.org/samba/security/CVE-2023-34968.htmlmitre
News mentions
0No linked articles in our index yet.