CVE-2023-5369

CVE-2023-5369: copy_file_range insufficient capability rights check

Vendor Freebsd
Product FreeBSD
Weakness CWE-273
Published October 4, 2023
Last update February 13, 2025

CVSS base score

What the vulnerability does

01Description

Before correction, the copy_file_range system call checked only for the CAP_READ and CAP_WRITE capabilities on the input and output file descriptors, respectively. Using an offset is logically equivalent to seeking, and the system call must additionally require the CAP_SEEK capability. This incorrect privilege check enabled sandboxed processes with only read or write but no seek capability on a file descriptor to read data from or write data to an arbitrary location within the file corresponding to that file descriptor.

Key dates

02Disclosure timeline

October 4, 2023 CVE published
February 13, 2025 Record updated