PT-2021-3330 · Samba+9 · Samba+9

Peter Eriksson

·

Published

2021-04-14

·

Updated

2026-01-30

·

CVE-2021-20254

CVSS v2.0

8.5

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions Samba versions prior to 4.12.15 Samba versions prior to 4.13.8 Samba versions prior to 4.14.4
Description A flaw was found in Samba that could allow it to read data beyond the end of the array in the case where a negative cache entry had been added to the mapping cache. This could cause the calling code to return those values into the process token that stores the group membership for a user. The highest threat from this vulnerability is to data confidentiality and integrity. In most cases, it may lead to a crash of the smbd process, but in the worst-case scenario, it may allow unauthorized access to files and deletion of files by a non-privileged user on the network share.
Recommendations For Samba versions prior to 4.12.15, update to version 4.12.15 or later. For Samba versions prior to 4.13.8, update to version 4.13.8 or later. For Samba versions prior to 4.14.4, update to version 4.14.4 or later.

Fix

DoS

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2021:4058
ALT-PU-2021-1766
ALT-PU-2021-1773
ALT-PU-2021-2045
ALT-PU-2021-2081
AZL-36999
AZL-7352
BDU:2021-03130
CESA-2021_2313
CESA-2021_4058
CVE-2021-20254
DLA-2668-1
ECHO-3F66-59C9-67B2
MGASA-2021-0287
OESA-2021-1207
OPENSUSE-SU-2021:0636-1
OPENSUSE-SU-2021:3187-1
OPENSUSE-SU-2021_0636-1
OPENSUSE-SU-2021_3187-1
OPENSUSE-SU-2024:11365-1
RHSA-2021:2313
RHSA-2021:3723
RHSA-2021:3724
RHSA-2021:3988
RHSA-2021:4058
RHSA-2021:4866
RHSA-2021_2313
RHSA-2021_4058
RLSA-2021:4058
SUSE-SU-2021:1438-1
SUSE-SU-2021:1439-1
SUSE-SU-2021:1440-1
SUSE-SU-2021:1442-1
SUSE-SU-2021:1444-1
SUSE-SU-2021:1445-1
SUSE-SU-2021:14709-1
SUSE-SU-2021:1492-1
SUSE-SU-2021:1498-1
SUSE-SU-2021:3187-1
SUSE-SU-2021_1438-1
SUSE-SU-2021_1439-1
SUSE-SU-2021_1442-1
SUSE-SU-2021_1445-1
SUSE-SU-2021_14709-1
SUSE-SU-2021_1492-1
SUSE-SU-2022:0361-1
USN-4930-1
USN-4931-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Red Hat
Rocky Linux
Samba
Suse
Ubuntu