Samba · Samba · CVE-2021-44142
**Name of the Vulnerable Software and Affected Versions**
Samba versions prior to 4.13.17
Samba versions prior to 4.14.12
Samba versions prior to 4.15.5
**Description**
The Samba vfs fruit module uses extended file attributes to provide enhanced compatibility with Apple SMB clients and interoperability with a Netatalk 3 AFP fileserver. A remote attacker with write access to extended file attributes can execute arbitrary code with the privileges of smbd, typically root. The vulnerability is related to an out-of-bounds heap read and write via specially crafted extended file attributes. The affected module is used for enhanced compatibility with Apple SMB clients and Netatalk 3 AFP file servers.
**Recommendations**
For Samba versions prior to 4.13.17, update to version 4.13.17 or apply the corresponding patches.
For Samba versions prior to 4.14.12, update to version 4.14.12 or apply the corresponding patches.
For Samba versions prior to 4.15.5, update to version 4.15.5 or apply the corresponding patches.
As a temporary workaround, consider restricting access to the vulnerable vfs fruit module to minimize the risk of exploitation.