PT-2021-8090 · Samba+6 · Samba+6

Andrew Bartlett

·

Published

2021-04-26

·

Updated

2025-08-21

·

CVE-2021-3670

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Samba (affected versions not specified)
Description The issue is related to the MaxQueryDuration not being honored in Samba AD DC LDAP, which can lead to uncontrolled resource consumption. This can allow a remote attacker to cause a denial of service.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Resource Exhaustion

Weakness Enumeration

Related Identifiers

ALT-PU-2022-1003
ALT-PU-2022-1004
ALT-PU-2022-1477
ALT-PU-2022-1478
ALT-PU-2023-1615
ALT-PU-2023-1616
AZL-10662
BDU:2024-06958
CVE-2021-3670
OESA-2022-1735
OESA-2024-1703
OPENSUSE-SU-2022_1576-1
OPENSUSE-SU-2022_2307-1
OPENSUSE-SU-2024:11882-1
SUSE-SU-2022:1576-1
SUSE-SU-2022:2307-1
SUSE-SU-2022_1576-1
SUSE-SU-2022_2307-1
USN-5542-1

Affected Products

Alt Linux
Astra Linux
Debian
Linuxmint
Samba
Suse
Ubuntu