CVE-2023-4091: Fedoraproject Fedora
Medium severity, CVSS 6.5. EPSS: 1.2% chance of exploitation in the next 30 days.
A vulnerability was discovered in Samba, where the flaw allows SMB clients to truncate files, even with read-only permissions when the Samba VFS module "acl_xattr" is configured with "acl_xattr:ignore system acls = yes". The SMB protocol allows opening files when the client requests read-only access but then implicitly truncates the opened file to 0 bytes if the client specifies a separate OVERWRITE create disposition request. The issue arises in configurations that bypass kernel file system permissions checks, relying solely on Samba's permissions.
Affected products
- Fedoraproject Fedora: version 39 only
- Red Hat Enterprise Linux: version 8.0 only
- Red Hat Enterprise Linux Eus: version 9.0 only
- Red Hat Storage: version 3.0 only
- Samba Samba: before 4.17.12 (fixed in 4.17.12); from 4.18.0, before 4.18.8 (fixed in 4.18.8); from 4.19.0, before 4.19.1 (fixed in 4.19.1)
Published 2023-11-03. Last modified 2026-06-17.