PT-2018-2508 · Samba+3 · Samba+3

Alex Maccuish

·

Published

2018-10-24

·

Updated

2024-06-15

·

CVE-2018-16841

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Samba versions 4.3.0 through 4.7.11 Samba versions 4.8.0 through 4.8.6 Samba versions 4.9.0 through 4.9.2
Description The issue is related to a denial of service when Samba is configured to accept smart-card authentication. In this scenario, Samba's KDC will call talloc free() twice on the same memory if the principal in a validly signed certificate does not match the principal in the AS-REQ. This can only occur after authentication with a trusted certificate. The talloc function is robust against further corruption from a double-free with talloc free() and directly calls abort(), terminating the KDC process.
Recommendations For Samba versions 4.3.0 through 4.7.11, update to version 4.7.12 or later. For Samba versions 4.8.0 through 4.8.6, update to version 4.8.7 or later. For Samba versions 4.9.0 through 4.9.2, update to version 4.9.3 or later. As a temporary workaround, consider disabling smart-card authentication until a patch is available.

Fix

DoS

Double Free

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-2743
ALT-PU-2018-2744
BDU:2019-00878
CVE-2018-16841
DSA-4345-1
ECHO-3243-5F1A-98B7
MGASA-2019-0011
OPENSUSE-SU-2024:11365-1
SUSE-SU-2018:4066-1
USN-3827-1
USN-3827-2

Affected Products

Alt Linux
Samba
Suse
Ubuntu