cbcvebase.
CVE-2018-16841
published 2018-11-28

CVE-2018-16841: Samba from version 4.3.0 and before versions 4.7.12, 4.8.7 and 4.9.3 are vulnerable to a denial of service. When configured to accept smart-card…

PriorityP338medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
4.59%
90.6th percentile
Samba from version 4.3.0 and before versions 4.7.12, 4.8.7 and 4.9.3 are vulnerable to a denial of service. When configured to accept smart-card authentication, Samba's KDC will call talloc_free() twice on the same memory if the principal in a validly signed certificate does not match the principal in the AS-REQ. This is only possible after authentication with a trusted certificate. talloc is robust against further corruption from a double-free with talloc_free() and directly calls abort(), terminating the KDC process.

Affected

17 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiansamba< samba 2:4.9.2+dfsg-2 (bookworm)samba 2:4.9.2+dfsg-2 (bookworm)
sambasamba>= 0 < 2:4.9.2+dfsg-22:4.9.2+dfsg-2
sambasamba>= 0 < 2:4.9.2+dfsg-22:4.9.2+dfsg-2
sambasamba>= 0 < 2:4.9.2+dfsg-22:4.9.2+dfsg-2
sambasamba>= 0 < 2:4.9.2+dfsg-22:4.9.2+dfsg-2
sambasamba>= 0 < 2:4.3.11+dfsg-0ubuntu0.14.04.192:4.3.11+dfsg-0ubuntu0.14.04.19
sambasamba>= 0 < 2:4.3.11+dfsg-0ubuntu0.16.04.182:4.3.11+dfsg-0ubuntu0.16.04.18
sambasamba>= 0 < 2:4.7.6+dfsg~ubuntu-0ubuntu2.52:4.7.6+dfsg~ubuntu-0ubuntu2.5
sambasamba>= 4.3.0 < 4.7.124.7.12
sambasamba>= 4.8.0 < 4.8.74.8.7
sambasamba>= 4.9.0 < 4.9.34.9.3

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv3.05.7MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.