CVE-2021-44142

Updated: 2023-09-18 21:00:04.315325

Description:

The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "...enhanced compatibility with Apple SMB clients and interoperability with a Netatalk 3 AFP fileserver." Samba versions prior to 4.13.17, 4.14.12 and 4.15.5 with vfs_fruit configured allow out-of-bounds heap read and write via specially crafted extended file attributes. A remote attacker with write access to extended file attributes can execute arbitrary code with the privileges of smbd, typically root.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x HIGH 9
CVSS Version 3.x HIGH 8.8

Status

OS name Project name Version Score Severity Status Errata Last updated
CentOS 6 ELS samba 3.6.23 8.8 HIGH Not Vulnerable 2022-02-23 14:48:36
CentOS 8.4 ELS samba 4.13.3-5 8.8 HIGH Released CLSA-2022:1643917481 2022-02-23 14:48:36
CentOS 8.5 ELS samba 4.14.5-7 8.8 HIGH Released CLSA-2022:1643914257 2022-02-23 14:48:36
CloudLinux 6 ELS samba 3.6.23 8.8 HIGH Not Vulnerable 2022-02-23 14:48:36
Oracle Linux 6 ELS samba 3.6.23 8.8 HIGH Not Vulnerable 2022-02-23 14:48:36
Ubuntu 16.04 ELS samba 4.3.11 8.8 HIGH Released CLSA-2022:1644501113 2022-02-23 14:48:36
Ubuntu 18.04 ELS samba 4.7.6 8.8 HIGH Already Fixed 2023-06-02 09:10:35