PT-2022-1452 · Samba+10 · Samba+10

Billy Jheng Bing-Jhong

+5

·

Published

2021-12-13

·

Updated

2026-03-10

·

CVE-2021-44142

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Samba versions prior to 4.13.17 Samba versions prior to 4.14.12 Samba versions prior to 4.15.5
Description The Samba vfs fruit module uses extended file attributes to provide enhanced compatibility with Apple SMB clients and interoperability with a Netatalk 3 AFP fileserver. A remote attacker with write access to extended file attributes can execute arbitrary code with the privileges of smbd, typically root. The vulnerability is related to an out-of-bounds heap read and write via specially crafted extended file attributes. The affected module is used for enhanced compatibility with Apple SMB clients and Netatalk 3 AFP file servers.
Recommendations For Samba versions prior to 4.13.17, update to version 4.13.17 or apply the corresponding patches. For Samba versions prior to 4.14.12, update to version 4.14.12 or apply the corresponding patches. For Samba versions prior to 4.15.5, update to version 4.15.5 or apply the corresponding patches. As a temporary workaround, consider restricting access to the vulnerable vfs fruit module to minimize the risk of exploitation.

Exploit

Fix

DoS

Out of bounds Read

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2021_5082
ALSA-2022:0332
ALSA-2022_0332
ALSA-2022_2074
ALSA-2022_7111
ALSA-2022_7730
ALSA-2022_8317
ALSA-2022_8318
ALSA-2025_16880
ALT-PU-2022-1442
ALT-PU-2022-1478
ALT-PU-2023-1616
AZL-37008
AZL-8611
BDU:2022-00579
CESA-2022_0328
CESA-2022_0332
CVE-2021-44142
DSA-5071-1
ECHO-8DD7-1492-D324
ELSA-2022-0328
ELSA-2022-0332
MGASA-2022-0054
OESA-2022-1524
OPENSUSE-SU-2022:0283-1
OPENSUSE-SU-2022_0283-1
OPENSUSE-SU-2022_0284-1
OPENSUSE-SU-2022_0287-1
OPENSUSE-SU-2024:11807-1
RHSA-2022:0328
RHSA-2022:0329
RHSA-2022:0330
RHSA-2022:0331
RHSA-2022:0332
RHSA-2022:0457
RHSA-2022:0458
RHSA-2022:0663
RHSA-2022:0664
RHSA-2022_0328
RHSA-2022_0332
RLSA-2022:0332
RLSA-2022_0332
SUSE-SU-2022:0251-1
SUSE-SU-2022:0252-1
SUSE-SU-2022:0271-1
SUSE-SU-2022:0283-1
SUSE-SU-2022:0284-1
SUSE-SU-2022:0287-1
SUSE-SU-2022:0323-1
SUSE-SU-2022:0361-1
SUSE-SU-2022_0251-1
SUSE-SU-2022_0252-1
SUSE-SU-2022_0271-1
SUSE-SU-2022_0283-1
SUSE-SU-2022_0284-1
SUSE-SU-2022_0287-1
SUSE-SU-2022_0323-1
USN-5260-1
USN-5260-2
USN-5260-3
ZDI-22-244
ZDI-22-245
ZDI-22-246

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Red Hat
Red Os
Rocky Linux
Samba
Suse
Ubuntu