CVE-2021-20254 — Out-of-bounds Read in Samba
Severity
6.8MEDIUMNVD
OSV4.3
EPSS
1.8%
top 17.34%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 5
Latest updateMay 24
Description
A flaw was found in samba. The Samba smbd file server must map Windows group identities (SIDs) into unix group ids (gids). The code that performs this had a flaw that could allow it to read data beyond the end of the array in the case where a negative cache entry had been added to the mapping cache. This could cause the calling code to return those values into the process token that stores the group membership for a user. The highest threat from this vulnerability is to data confidentiality and …
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:NExploitability: 1.6 | Impact: 5.2
Affected Packages8 packages
Also affects: Debian Linux 9.0, Fedora 32, 33, Enterprise Linux 7.0, 8.0
🔴Vulnerability Details
3📋Vendor Advisories
5Microsoft▶
A flaw was found in samba. The Samba smbd file server must map Windows group identities (SIDs) into unix group ids (gids). The code that performs this had a flaw that could allow it to read data beyon↗2021-05-11
Red Hat▶
samba: Negative idmap cache entries can cause incorrect group entries in the Samba file server process token↗2021-04-29
Debian▶
CVE-2021-20254: samba - A flaw was found in samba. The Samba smbd file server must map Windows group ide...↗2021