CVE-2023-34968: Debian Linux
Medium severity, CVSS 5.3. EPSS: 1.3% chance of exploitation in the next 30 days.
A path disclosure vulnerability was found in Samba. As part of the Spotlight protocol, Samba discloses the server-side absolute path of shares, files, and directories in the results for search queries. This flaw allows a malicious client or an attacker with a targeted RPC request to view the information that is part of the disclosed path.
Affected products
- Debian Debian Linux: version 11.0 only; version 12.0 only
- Fedoraproject Fedora: version 37 only; version 38 only
- Red Hat Enterprise Linux: version 8.0 only; version 9.0 only
- Red Hat Storage: version 3.0 only
- Samba Samba: before 4.16.11 (fixed in 4.16.11); from 4.17.0, before 4.17.10 (fixed in 4.17.10); from 4.18.0, before 4.18.5 (fixed in 4.18.5)
Published 2023-07-20. Last modified 2026-06-17.