cbcvebase.
CVE-2009-2906
published 2009-10-07

CVE-2009-2906: smbd in Samba 3.0 before 3.0.37, 3.2 before 3.2.15, 3.3 before 3.3.8, and 3.4 before 3.4.2 allows remote authenticated users to cause a denial of service…

PriorityP417medium4CVSS 2.0
AVNACLAuSCNINAP
EPSS
4.21%
89.9th percentile
smbd in Samba 3.0 before 3.0.37, 3.2 before 3.2.15, 3.3 before 3.3.8, and 3.4 before 3.4.2 allows remote authenticated users to cause a denial of service (infinite loop) via an unanticipated oplock break notification reply packet.

Affected

14 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiansamba< samba 2:3.4.2-1 (bookworm)samba 2:3.4.2-1 (bookworm)
sambasamba< 3.0.373.0.37
sambasamba
sambasamba
sambasamba>= 0 < 2:3.4.2-12:3.4.2-1
sambasamba>= 0 < 2:3.4.2-12:3.4.2-1
sambasamba>= 0 < 2:3.4.2-12:3.4.2-1
sambasamba>= 0 < 2:3.4.2-12:3.4.2-1
sambasamba>= 3.2.0 < 3.2.153.2.15
sambasamba>= 3.3.0 < 3.3.83.3.8

CVSS provenance

nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
osv4.0MEDIUM
vendor_ubuntu9.3CRITICAL
vendor_debian4.0LOW
vendor_redhat4.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.