Medium severity6.5NVD Advisory· Published Nov 3, 2023· Updated Jun 17, 2026
CVE-2023-4091
CVE-2023-4091
Description
A vulnerability was discovered in Samba, where the flaw allows SMB clients to truncate files, even with read-only permissions when the Samba VFS module "acl_xattr" is configured with "acl_xattr:ignore system acls = yes". The SMB protocol allows opening files when the client requests read-only access but then implicitly truncates the opened file to 0 bytes if the client specifies a separate OVERWRITE create disposition request. The issue arises in configurations that bypass kernel file system permissions checks, relying solely on Samba's permissions.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
73- Red Hat/Red Hat Enterprise Linux 8.8 Extended Update Supportv5cpe:/a:redhat:rhel_eus:8.8::appstreamRange: 0:4.17.5-4.el8_8
- Red Hat/Red Hat Enterprise Linux 9.0 Extended Update Supportv5cpe:/a:redhat:rhel_eus:9.0::resilientstorageRange: 0:4.15.5-111.el9_0
- Red Hat/Red Hat Enterprise Linux 9.2 Extended Update Supportv5cpe:/a:redhat:rhel_eus:9.2::appstreamRange: 0:4.17.5-104.el9_2
- cpe:/a:redhat:storage:3
cpe:/o:redhat:enterprise_linux:6+ 4 more
- cpe:/o:redhat:enterprise_linux:6
- cpe:/o:redhat:enterprise_linux:7
- cpe:/o:redhat:enterprise_linux:8::baseosrange: 0:4.18.6-2.el8_9
- cpe:/o:redhat:enterprise_linux:9::baseosrange: 0:4.18.6-101.el9_3
- cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
- cpe:/o:redhat:rhel_eus:8.6::baseosRange: 0:4.15.5-13.el8_6
cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*range: <4.17.12
- (no CPE)
- cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_eus:9.0:*:*:*:*:*:*:*
- osv-coords58 versionspkg:deb/ubuntu/samba@2:4.18.6+dfsg-1ubuntu2.1?arch=source&distro=manticpkg:rpm/almalinux/ctdbpkg:rpm/almalinux/libnetapipkg:rpm/almalinux/libnetapi-develpkg:rpm/almalinux/libsmbclientpkg:rpm/almalinux/libsmbclient-develpkg:rpm/almalinux/libwbclientpkg:rpm/almalinux/libwbclient-develpkg:rpm/almalinux/python3-sambapkg:rpm/almalinux/python3-samba-dcpkg:rpm/almalinux/python3-samba-develpkg:rpm/almalinux/python3-samba-testpkg:rpm/almalinux/sambapkg:rpm/almalinux/samba-clientpkg:rpm/almalinux/samba-client-libspkg:rpm/almalinux/samba-commonpkg:rpm/almalinux/samba-common-libspkg:rpm/almalinux/samba-common-toolspkg:rpm/almalinux/samba-dc-libspkg:rpm/almalinux/samba-dcerpcpkg:rpm/almalinux/samba-develpkg:rpm/almalinux/samba-krb5-printingpkg:rpm/almalinux/samba-ldb-ldap-modulespkg:rpm/almalinux/samba-libspkg:rpm/almalinux/samba-pidlpkg:rpm/almalinux/samba-testpkg:rpm/almalinux/samba-test-libspkg:rpm/almalinux/samba-toolspkg:rpm/almalinux/samba-usersharespkg:rpm/almalinux/samba-vfs-iouringpkg:rpm/almalinux/samba-winbindpkg:rpm/almalinux/samba-winbind-clientspkg:rpm/almalinux/samba-winbind-krb5-locatorpkg:rpm/almalinux/samba-winbind-modulespkg:rpm/almalinux/samba-winexepkg:rpm/opensuse/samba&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/samba&distro=openSUSE%20Leap%2015.5pkg:rpm/opensuse/samba&distro=openSUSE%20Tumbleweedpkg:rpm/suse/samba&distro=SUSE%20Enterprise%20Storage%207.1pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2012%20SP5pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2015%20SP3pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2015%20SP4pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2015%20SP5pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP3-ESPOSpkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP3-LTSSpkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Micro%205.2pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Micro%205.3pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Micro%205.4pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Micro%205.5pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP4pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP5pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP3-LTSSpkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP3pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5pkg:rpm/suse/samba&distro=SUSE%20Manager%20Proxy%204.2pkg:rpm/suse/samba&distro=SUSE%20Manager%20Server%204.2
< 2:4.18.6+dfsg-1ubuntu2.1+ 57 more
- (no CPE)range: < 2:4.18.6+dfsg-1ubuntu2.1
- (no CPE)range: < 4.18.6-101.el9_3.alma.1
- (no CPE)range: < 4.18.6-101.el9_3.alma.1
- (no CPE)range: < 4.18.6-101.el9_3.alma.1
- (no CPE)range: < 4.18.6-101.el9_3.alma.1
- (no CPE)range: < 4.18.6-101.el9_3.alma.1
- (no CPE)range: < 4.18.6-101.el9_3.alma.1
- (no CPE)range: < 4.18.6-101.el9_3.alma.1
- (no CPE)range: < 4.18.6-101.el9_3.alma.1
- (no CPE)range: < 4.18.6-101.el9_3.alma.1
- (no CPE)range: < 4.18.6-101.el9_3.alma.1
- (no CPE)range: < 4.18.6-101.el9_3.alma.1
- (no CPE)range: < 4.18.6-101.el9_3.alma.1
- (no CPE)range: < 4.18.6-101.el9_3.alma.1
- (no CPE)range: < 4.18.6-101.el9_3.alma.1
- (no CPE)range: < 4.18.6-101.el9_3.alma.1
- (no CPE)range: < 4.18.6-101.el9_3.alma.1
- (no CPE)range: < 4.18.6-101.el9_3.alma.1
- (no CPE)range: < 4.18.6-101.el9_3.alma.1
- (no CPE)range: < 4.18.6-101.el9_3.alma.1
- (no CPE)range: < 4.18.6-101.el9_3.alma.1
- (no CPE)range: < 4.18.6-101.el9_3.alma.1
- (no CPE)range: < 4.18.6-101.el9_3.alma.1
- (no CPE)range: < 4.18.6-101.el9_3.alma.1
- (no CPE)range: < 4.18.6-101.el9_3.alma.1
- (no CPE)range: < 4.18.6-101.el9_3.alma.1
- (no CPE)range: < 4.18.6-101.el9_3.alma.1
- (no CPE)range: < 4.18.6-101.el9_3.alma.1
- (no CPE)range: < 4.18.6-101.el9_3.alma.1
- (no CPE)range: < 4.18.6-101.el9_3.alma.1
- (no CPE)range: < 4.18.6-101.el9_3.alma.1
- (no CPE)range: < 4.18.6-101.el9_3.alma.1
- (no CPE)range: < 4.18.6-101.el9_3.alma.1
- (no CPE)range: < 4.18.6-101.el9_3.alma.1
- (no CPE)range: < 4.18.6-101.el9_3.alma.1
- (no CPE)range: < 4.15.13+git.691.3d3cea0641-150400.3.31.1
- (no CPE)range: < 4.17.9+git.421.abde31ca5c2-150500.3.11.1
- (no CPE)range: < 4.19.1+git.312.c912b3d2ef6-1.1
- (no CPE)range: < 4.15.13+git.691.3d3cea0641-150300.3.63.1
- (no CPE)range: < 4.15.13+git.625.ac658f2f12-3.88.1
- (no CPE)range: < 4.15.13+git.691.3d3cea0641-150300.3.63.1
- (no CPE)range: < 4.15.13+git.691.3d3cea0641-150400.3.31.1
- (no CPE)range: < 4.17.9+git.421.abde31ca5c2-150500.3.11.1
- (no CPE)range: < 4.15.13+git.691.3d3cea0641-150300.3.63.1
- (no CPE)range: < 4.15.13+git.691.3d3cea0641-150300.3.63.1
- (no CPE)range: < 4.15.13+git.691.3d3cea0641-150300.3.63.1
- (no CPE)range: < 4.15.13+git.691.3d3cea0641-150400.3.31.1
- (no CPE)range: < 4.15.13+git.691.3d3cea0641-150400.3.31.1
- (no CPE)range: < 4.17.9+git.421.abde31ca5c2-150500.3.11.1
- (no CPE)range: < 4.15.13+git.691.3d3cea0641-150400.3.31.1
- (no CPE)range: < 4.17.9+git.421.abde31ca5c2-150500.3.11.1
- (no CPE)range: < 4.15.13+git.625.ac658f2f12-3.88.1
- (no CPE)range: < 4.15.13+git.691.3d3cea0641-150300.3.63.1
- (no CPE)range: < 4.15.13+git.625.ac658f2f12-3.88.1
- (no CPE)range: < 4.15.13+git.691.3d3cea0641-150300.3.63.1
- (no CPE)range: < 4.15.13+git.625.ac658f2f12-3.88.1
- (no CPE)range: < 4.15.13+git.691.3d3cea0641-150300.3.63.1
- (no CPE)range: < 4.15.13+git.691.3d3cea0641-150300.3.63.1
Patches
Vulnerability mechanics
References
13- access.redhat.com/errata/RHSA-2023:6209nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2023:6744nvdThird Party Advisory
- access.redhat.com/security/cve/CVE-2023-4091nvdThird Party Advisory
- www.samba.org/samba/security/CVE-2023-4091.htmlnvdVendor Advisory
- bugzilla.redhat.com/show_bug.cginvdIssue Tracking
- bugzilla.samba.org/show_bug.cginvdIssue Tracking
- access.redhat.com/errata/RHSA-2023:7371nvd
- access.redhat.com/errata/RHSA-2023:7408nvd
- access.redhat.com/errata/RHSA-2023:7464nvd
- access.redhat.com/errata/RHSA-2023:7467nvd
- lists.debian.org/debian-lts-announce/2024/04/msg00015.htmlnvd
- lists.fedoraproject.org/archives/list/[email protected]/message/ZUMVALLFFDFC53JZMUWA6HPD7HUGAP5I/nvd
- security.netapp.com/advisory/ntap-20231124-0002/nvd
News mentions
0No linked articles in our index yet.