This incorrect privilege check enabled sandboxed processes with only read or write but no seek capability on a file descriptor to read data from or write data to an arbitrary location within the file corresponding to that file descriptor.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-57685 | Before correction, the copy_file_range system call checked only for the CAP_READ and CAP_WRITE capabilities on the input and output file descriptors, respectively. Using an offset is logically equivalent to seeking, and the system call must additionally require the CAP_SEEK capability. This incorrect privilege check enabled sandboxed processes with only read or write but no seek capability on a file descriptor to read data from or write data to an arbitrary location within the file corresponding to that file descriptor. |
Fri, 20 Sep 2024 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: freebsd
Published:
Updated: 2025-02-13T17:20:10.344Z
Reserved: 2023-10-03T21:25:17.658Z
Link: CVE-2023-5369
Updated: 2024-08-02T07:59:43.255Z
Status : Modified
Published: 2023-10-04T04:15:14.627
Modified: 2024-11-21T08:41:37.637
Link: CVE-2023-5369
No data.
OpenCVE Enrichment
No data.
EUVD