{"id":"UBUNTU-CVE-2023-28938","details":"Uncontrolled resource consumption in some Intel(R) SSD Tools software before version mdadm-4.2-rc2 may allow a priviledged user to potentially enable denial of service via local access.","modified":"2025-10-24T05:01:54Z","published":"2023-08-11T03:15:00Z","upstream":["CVE-2023-28938"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-28938"},{"type":"REPORT","url":"https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00690.html"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2023-28938"}],"affected":[{"package":{"name":"mdadm","ecosystem":"Ubuntu:14.04:LTS","purl":"pkg:deb/ubuntu/mdadm@3.2.5-5ubuntu4.4?arch=source&distro=trusty"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["3.2.5-5ubuntu2","3.2.5-5ubuntu3","3.2.5-5ubuntu4","3.2.5-5ubuntu4.1","3.2.5-5ubuntu4.2","3.2.5-5ubuntu4.3","3.2.5-5ubuntu4.4"],"ecosystem_specific":{"binaries":[{"binary_name":"mdadm","binary_version":"3.2.5-5ubuntu4.4"}],"priority_reason":"Denial of service in command line tool option only"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-28938.json"}},{"package":{"name":"mdadm","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/mdadm@3.3-2ubuntu7.6?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["3.3-2ubuntu2","3.3-2ubuntu3","3.3-2ubuntu4","3.3-2ubuntu5","3.3-2ubuntu6","3.3-2ubuntu7","3.3-2ubuntu7.1","3.3-2ubuntu7.2","3.3-2ubuntu7.4","3.3-2ubuntu7.5","3.3-2ubuntu7.6"],"ecosystem_specific":{"binaries":[{"binary_name":"mdadm","binary_version":"3.3-2ubuntu7.6"}],"priority_reason":"Denial of service in command line tool option only"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-28938.json"}},{"package":{"name":"mdadm","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/mdadm@4.1~rc1-3~ubuntu18.04.4?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["4.0-2","4.0-2ubuntu1","4.0-2ubuntu1.1","4.1~rc1-3~ubuntu18.04.1","4.1~rc1-3~ubuntu18.04.2","4.1~rc1-3~ubuntu18.04.4"],"ecosystem_specific":{"binaries":[{"binary_name":"mdadm","binary_version":"4.1~rc1-3~ubuntu18.04.4"}],"priority_reason":"Denial of service in command line tool option only"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-28938.json"}},{"package":{"name":"mdadm","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/mdadm@4.1-5ubuntu1.2?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["4.1-2ubuntu3","4.1-4ubuntu1","4.1-5ubuntu1","4.1-5ubuntu1.2"],"ecosystem_specific":{"binaries":[{"binary_name":"mdadm","binary_version":"4.1-5ubuntu1.2"}],"priority_reason":"Denial of service in command line tool option only"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-28938.json"}},{"package":{"name":"mdadm","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/mdadm@4.2-0ubuntu2?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["4.2~rc2-2ubuntu1","4.2-0ubuntu1","4.2-0ubuntu2"],"ecosystem_specific":{"binaries":[{"binary_name":"mdadm","binary_version":"4.2-0ubuntu2"}],"priority_reason":"Denial of service in command line tool option only"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-28938.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:L"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H"},{"type":"Ubuntu","score":"low"}]}