UBUNTU-CVE-2023-52443

    Dashboard / Vulnerabilities / UBUNTU-CVE-2023-52443

    UBUNTU-CVE-2023-52443

    Published: 22 Feb 2024Last Modified: 22 Sept 2026
    Upstream:
    Aliases:

    Summary:

    Details: In the Linux kernel, the following vulnerability has been resolved: apparmor: avoid crash when parsed profile name is empty When processing a packed profile in unpack_profile() described like "profile :ns::samba-dcerpcd /usr/lib*/samba/{,samba/}samba-dcerpcd {...}" a string ":samba-dcerpcd" is unpacked as a fully-qualified name and then passed to aa_splitn_fqname(). aa_splitn_fqname() treats ":samba-dcerpcd" as only containing a namespace. Thus it returns NULL for tmpname, meanwhile tmpns is non-NULL. Later aa_alloc_profile() crashes as the new profile name is NULL now. general protection fault, probably for non-canonical address 0xdffffc0000000000: 0000 [#1] PREEMPT SMP KASAN NOPTI KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007] CPU: 6 PID: 1657 Comm: apparmor_parser Not tainted 6.7.0-rc2-dirty #16 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.2-3-gd478f380-rebuilt.opensuse.org 04/01/2014 RIP: 0010:strlen+0x1e/0xa0 Call Trace: <TASK> ? strlen+0x1e/0xa0 aa_policy_init+0x1bb/0x230 aa_alloc_profile+0xb1/0x480 unpack_profile+0x3bc/0x4960 aa_unpack+0x309/0x15e0 aa_replace_profiles+0x213/0x33c0 policy_update+0x261/0x370 profile_replace+0x20e/0x2a0 vfs_write+0x2af/0xe00 ksys_write+0x126/0x250 do_syscall_64+0x46/0xf0 entry_SYSCALL_64_after_hwframe+0x6e/0x76 </TASK> ---[ end trace 0000000000000000 ]--- RIP: 0010:strlen+0x1e/0xa0 It seems such behaviour of aa_splitn_fqname() is expected and checked in other places where it is called (e.g. aa_remove_profiles). Well, there is an explicit comment "a ns name without a following profile is allowed" inside. AFAICS, nothing can prevent unpacked "name" to be in form like ":samba-dcerpcd" - it is passed from userspace. Deny the whole profile set replacement in such case and inform user with EPROTO and an explaining message. Found by Linux Verification Center (linuxtesting.org).

    References: https://ubuntu.com/security/CVE-2023-52443, https://git.kernel.org/stable/c/9286ee97aa4803d99185768735011d0d65827c9e, https://git.kernel.org/stable/c/1d8e62b5569cc1466ceb8a7e4872cf10160a9dcf, https://git.kernel.org/stable/c/5ff00408e5029d3550ee77f62dc15f1e15c47f87, https://git.kernel.org/stable/c/0a12db736edbb4933e4274932aeea594b5876fa4, https://git.kernel.org/stable/c/9d4fa5fe2b1d56662afd14915a73b4d0783ffa45, https://git.kernel.org/stable/c/5c0392fdafb0a2321311900be83ffa572bef8203, https://git.kernel.org/stable/c/77ab09b92f16c8439a948d1af489196953dc4a0e, https://git.kernel.org/stable/c/55a8210c9e7d21ff2644809699765796d4bfb200, https://ubuntu.com/security/notices/USN-6688-1, https://ubuntu.com/security/notices/USN-6725-1, https://ubuntu.com/security/notices/USN-6726-1, https://www.cve.org/CVERecord?id=CVE-2023-52443, https://ubuntu.com/security/notices/USN-6725-2, https://ubuntu.com/security/notices/USN-6726-2, https://ubuntu.com/security/notices/USN-6726-3, https://ubuntu.com/security/notices/USN-6818-1, https://ubuntu.com/security/notices/USN-6819-1, https://ubuntu.com/security/notices/USN-6818-2, https://ubuntu.com/security/notices/USN-6819-2, https://ubuntu.com/security/notices/USN-6819-3, https://ubuntu.com/security/notices/USN-6818-3, https://ubuntu.com/security/notices/USN-6818-4, https://ubuntu.com/security/notices/USN-6819-4, https://ubuntu.com/security/notices/USN-6926-1, https://ubuntu.com/security/notices/USN-6926-2, https://ubuntu.com/security/notices/USN-6926-3

    Affected packages

    Package

    Name: linux-azure

    Purl: pkg:deb/ubuntu/linux-azure?arch=source&distro=trusty%2Fesm

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -4.15.0-1179.194~14.04.1

    Affected versions

    4.15.0-1023.24~14.04.1
    4.15.0-1030.31~14.04.1
    4.15.0-1031.32~14.04.1
    4.15.0-1032.33~14.04.2
    4.15.0-1035.36~14.04.2
    4.15.0-1036.38~14.04.2
    4.15.0-1037.39~14.04.2
    4.15.0-1039.41~14.04.2
    4.15.0-1040.44~14.04.1
    4.15.0-1041.45~14.04.1
    4.15.0-1042.46~14.04.1
    4.15.0-1045.49~14.04.1
    4.15.0-1046.50~14.04.1
    4.15.0-1047.51~14.04.1
    4.15.0-1049.54~14.04.1
    4.15.0-1050.55~14.04.1
    4.15.0-1051.56~14.04.1
    4.15.0-1052.57~14.04.1
    4.15.0-1055.60~14.04.1
    4.15.0-1056.61~14.04.1
    4.15.0-1057.62~14.04.1
    4.15.0-1059.64~14.04.1
    4.15.0-1060.65~14.04.1
    4.15.0-1061.66~14.04.1
    4.15.0-1063.68~14.04.1
    4.15.0-1064.69~14.04.1
    4.15.0-1066.71~14.04.1
    4.15.0-1067.72~14.04.1
    4.15.0-1069.74~14.04.1
    4.15.0-1071.76~14.04.1
    4.15.0-1074.79~14.04.1
    4.15.0-1077.82~14.04.1
    4.15.0-1082.92~14.04.1
    4.15.0-1083.93~14.04.1
    4.15.0-1089.99~14.04.1
    4.15.0-1091.101~14.04.1
    4.15.0-1092.102~14.04.1
    4.15.0-1093.103~14.04.1
    4.15.0-1095.105~14.04.1
    4.15.0-1096.106~14.04.1
    4.15.0-1098.109~14.04.1
    4.15.0-1100.111~14.04.1
    4.15.0-1102.113~14.04.1
    4.15.0-1103.114~14.04.1
    4.15.0-1106.118~14.04.1
    4.15.0-1108.120~14.04.1
    4.15.0-1109.121~14.04.1
    4.15.0-1110.122~14.04.1
    4.15.0-1111.123~14.04.1
    4.15.0-1112.124~14.04.1
    4.15.0-1113.126~14.04.1
    4.15.0-1114.127~14.04.1
    4.15.0-1115.128~14.04.1
    4.15.0-1118.131~14.04.1
    4.15.0-1121.134~14.04.1
    4.15.0-1122.135~14.04.1
    4.15.0-1123.136~14.04.1
    4.15.0-1124.137~14.04.1
    4.15.0-1125.138~14.04.1
    4.15.0-1126.139~14.04.1
    4.15.0-1127.140~14.04.1
    4.15.0-1129.142~14.04.1
    4.15.0-1130.143~14.04.1
    4.15.0-1131.144~14.04.1
    4.15.0-1133.146~14.04.1
    4.15.0-1134.147~14.04.1
    4.15.0-1136.149~14.04.1
    4.15.0-1137.150~14.04.1
    4.15.0-1138.151~14.04.1
    4.15.0-1139.152~14.04.1
    4.15.0-1142.156~14.04.1
    4.15.0-1145.160~14.04.1
    4.15.0-1146.161~14.04.1
    4.15.0-1149.164~14.04.1
    4.15.0-1150.165~14.04.1
    4.15.0-1151.166~14.04.1
    4.15.0-1153.168~14.04.1
    4.15.0-1157.172~14.04.2
    4.15.0-1158.173~14.04.1
    4.15.0-1159.174~14.04.1
    4.15.0-1162.177~14.04.1
    4.15.0-1163.178~14.04.1
    4.15.0-1164.179~14.04.1
    4.15.0-1165.180~14.04.1
    4.15.0-1166.181~14.04.1
    4.15.0-1167.182~14.04.1
    4.15.0-1168.183~14.04.1
    4.15.0-1169.184~14.04.1
    4.15.0-1170.185~14.04.1
    4.15.0-1171.186~14.04.1
    4.15.0-1172.187~14.04.1
    4.15.0-1173.188~14.04.1
    4.15.0-1174.189~14.04.1
    4.15.0-1175.190~14.04.1
    4.15.0-1176.191~14.04.1
    4.15.0-1177.192~14.04.1
    4.15.0-1178.193~14.04.1

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High