CVE-2021-20254
published 2021-05-05CVE-2021-20254: A flaw was found in samba. The Samba smbd file server must map Windows group identities (SIDs) into unix group ids (gids). The code that performs this had a…
PriorityP340medium6.8CVSS 3.1
AVNACHPRLUINSUCHIHAN
EPSS
1.62%
73.3th percentile
A flaw was found in samba. The Samba smbd file server must map Windows group identities (SIDs) into unix group ids (gids). The code that performs this had a flaw that could allow it to read data beyond the end of the array in the case where a negative cache entry had been added to the mapping cache. This could cause the calling code to return those values into the process token that stores the group membership for a user. The highest threat from this vulnerability is to data confidentiality and integrity.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | samba | < samba 2:4.13.5+dfsg-2 (bookworm) | samba 2:4.13.5+dfsg-2 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| msrc | azl3_samba_4.18.3-1_on_azure_linux_3.0 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| samba | samba | — | — |
| samba | samba | >= 0 < 2:4.13.5+dfsg-2 | 2:4.13.5+dfsg-2 |
| samba | samba | >= 0 < 2:4.13.5+dfsg-2 | 2:4.13.5+dfsg-2 |
| samba | samba | >= 0 < 2:4.13.5+dfsg-2 | 2:4.13.5+dfsg-2 |
| samba | samba | >= 0 < 2:4.13.5+dfsg-2 | 2:4.13.5+dfsg-2 |
| samba | samba | >= 0 < 2:4.3.11+dfsg-0ubuntu0.14.04.20+esm11 | 2:4.3.11+dfsg-0ubuntu0.14.04.20+esm11 |
| samba | samba | >= 3.6.0 < 4.12.15 | 4.12.15 |
| samba | samba | >= 4.13.0 < 4.13.8 | 4.13.8 |
| samba | samba | >= 4.14.0 < 4.14.4 | 4.14.4 |
CVSS provenance
nvdv3.16.8MEDIUMCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
nvdv2.04.9MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:N
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_msrc6.8MEDIUM
vendor_redhat6.8MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
A flaw was found in samba. The Samba smbd file server must map Windows group identities (SIDs) into unix group ids (gids). The code that performs this had a flaw that could allow it to read data beyon
vendor_msrc·2021-05-11·CVSS 6.8
CVE-2021-20254 [MEDIUM] CWE-125 A flaw was found in samba. The Samba smbd file server must map Windows group identities (SIDs) into unix group ids (gids). The code that performs this had a flaw that could allow it to read data beyon
A flaw was found in samba. The Samba smbd file server must map Windows group identities (SIDs) into unix group ids (gids). The code that performs this had a flaw that could allow it to read data beyond the end of the array in the case where a negative cache entry had been added to the mapping cache. This could cause the calling code to return those values into the process token that stores the group membership for a user. The highest threat from this vulnerability is to data confidentiality and integrity.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most rece
Ubuntu
Samba vulnerabilities
vendor_ubuntu·2021-05-03·CVSS 4.3
CVE-2020-14318 [MEDIUM] Samba vulnerabilities
Title: Samba vulnerabilities
Summary: Several security issues were fixed in Samba.
Steven French discovered that Samba incorrectly handled ChangeNotify
permissions. A remote attacker could possibly use this issue to obtain file
name information. (CVE-2020-14318)
Bas Alberts discovered that Samba incorrectly handled certain winbind
requests. A remote attacker could possibly use this issue to cause winbind
to crash, resulting in a denial of service. (CVE-2020-14323)
Francis Brosnan Blázquez discovered that Samba incorrectly handled certain
invalid DNS records. A remote attacker could possibly use this issue to
cause the DNS server to crash, resulting in a denial of service.
(CVE-2020-14383)
Peter Eriksson discovered that Samba incorrectly handled certain negative
idmap cache entries. Th
Red Hat
samba: Negative idmap cache entries can cause incorrect group entries in the Samba file server process token
vendor_redhat·2021-04-29·CVSS 6.8
CVE-2021-20254 [MEDIUM] CWE-125 samba: Negative idmap cache entries can cause incorrect group entries in the Samba file server process token
samba: Negative idmap cache entries can cause incorrect group entries in the Samba file server process token
A flaw was found in samba. The Samba smbd file server must map Windows group identities (SIDs) into unix group ids (gids). The code that performs this had a flaw that could allow it to read data beyond the end of the array in the case where a negative cache entry had been added to the mapping cache. This could cause the calling code to return those values into the process token that stores the group membership for a user. The highest threat from this vulnerability is to data confidentiality and integrity.
A flaw was found in samba. The Samba smbd file server must map Windows group identities (SIDs) into unix group ids (gids). The code that performs this had a flaw that could allow
Ubuntu
Samba vulnerability
vendor_ubuntu·2021-04-29
CVE-2021-20254 Samba vulnerability
Title: Samba vulnerability
Summary: Samba would allow unintended access to files over the network.
Peter Eriksson discovered that Samba incorrectly handled certain negative
idmap cache entries. This issue could result in certain users gaining
unauthorized access to files, contrary to expected behaviour.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2021-20254: samba - A flaw was found in samba. The Samba smbd file server must map Windows group ide...
vendor_debian·2021·CVSS 6.8
CVE-2021-20254 [MEDIUM] CVE-2021-20254: samba - A flaw was found in samba. The Samba smbd file server must map Windows group ide...
A flaw was found in samba. The Samba smbd file server must map Windows group identities (SIDs) into unix group ids (gids). The code that performs this had a flaw that could allow it to read data beyond the end of the array in the case where a negative cache entry had been added to the mapping cache. This could cause the calling code to return those values into the process token that stores the group membership for a user. The highest threat from this vulnerability is to data confidentiality and integrity.
Scope: local
bookworm: resolved (fixed in 2:4.13.5+dfsg-2)
bullseye: resolved (fixed in 2:4.13.5+dfsg-2)
forky: resolved (fixed in 2:4.13.5+dfsg-2)
sid: resolved (fixed in 2:4.13.5+dfsg-2)
trixie: resolved (fixed in 2:4.13.5+dfsg-2)
GHSA
GHSA-3r9x-25h6-9v89: A flaw was found in samba
ghsa_unreviewed·2022-05-24
CVE-2021-20254 [HIGH] CWE-125 GHSA-3r9x-25h6-9v89: A flaw was found in samba
A flaw was found in samba. The Samba smbd file server must map Windows group identities (SIDs) into unix group ids (gids). The code that performs this had a flaw that could allow it to read data beyond the end of the array in the case where a negative cache entry had been added to the mapping cache. This could cause the calling code to return those values into the process token that stores the group membership for a user. The highest threat from this vulnerability is to data confidentiality and integrity.
OSV
CVE-2021-20254: A flaw was found in samba
osv·2021-05-05·CVSS 6.8
CVE-2021-20254 [MEDIUM] CVE-2021-20254: A flaw was found in samba
A flaw was found in samba. The Samba smbd file server must map Windows group identities (SIDs) into unix group ids (gids). The code that performs this had a flaw that could allow it to read data beyond the end of the array in the case where a negative cache entry had been added to the mapping cache. This could cause the calling code to return those values into the process token that stores the group membership for a user. The highest threat from this vulnerability is to data confidentiality and integrity.
OSV
samba vulnerabilities
osv·2021-05-03·CVSS 4.3
CVE-2020-14318 [MEDIUM] samba vulnerabilities
samba vulnerabilities
Steven French discovered that Samba incorrectly handled ChangeNotify
permissions. A remote attacker could possibly use this issue to obtain file
name information. (CVE-2020-14318)
Bas Alberts discovered that Samba incorrectly handled certain winbind
requests. A remote attacker could possibly use this issue to cause winbind
to crash, resulting in a denial of service. (CVE-2020-14323)
Francis Brosnan Blázquez discovered that Samba incorrectly handled certain
invalid DNS records. A remote attacker could possibly use this issue to
cause the DNS server to crash, resulting in a denial of service.
(CVE-2020-14383)
Peter Eriksson discovered that Samba incorrectly handled certain negative
idmap cache entries. This issue could result in certain users gaining
unauthorized ac
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.redhat.com/show_bug.cgi?id=1949442https://lists.debian.org/debian-lts-announce/2021/05/msg00023.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3EP2VJ73OVBPVSOSTVOMGIEQA3MWF6F7/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZAF6L2M6CNAJ2YYYGXPWETTW5YLCWTVT/https://security.gentoo.org/glsa/202105-22https://security.netapp.com/advisory/ntap-20210430-0001/https://www.samba.org/samba/security/CVE-2021-20254.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1949442https://lists.debian.org/debian-lts-announce/2021/05/msg00023.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3EP2VJ73OVBPVSOSTVOMGIEQA3MWF6F7/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZAF6L2M6CNAJ2YYYGXPWETTW5YLCWTVT/https://security.gentoo.org/glsa/202105-22https://security.netapp.com/advisory/ntap-20210430-0001/https://www.samba.org/samba/security/CVE-2021-20254.html
2021-05-05
Published