CVE-2021-3671
published 2021-10-12CVE-2021-3671: A null pointer de-reference was found in the way samba kerberos server handled missing sname in TGS-REQ (Ticket Granting Server - Request). An authenticated…
PriorityP334medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
2.02%
78.8th percentile
A null pointer de-reference was found in the way samba kerberos server handled missing sname in TGS-REQ (Ticket Granting Server - Request). An authenticated user could use this flaw to crash the samba server.
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | heimdal | < heimdal 7.7.0+dfsg-3 (bookworm) | heimdal 7.7.0+dfsg-3 (bookworm) |
| debian | samba | < heimdal 7.7.0+dfsg-3 (bookworm) | heimdal 7.7.0+dfsg-3 (bookworm) |
| heimdal_project | heimdal | >= 0 < 7.7.0+dfsg-2+deb11u2 | 7.7.0+dfsg-2+deb11u2 |
| heimdal_project | heimdal | >= 0 < 7.7.0+dfsg-3 | 7.7.0+dfsg-3 |
| heimdal_project | heimdal | >= 0 < 7.7.0+dfsg-3 | 7.7.0+dfsg-3 |
| heimdal_project | heimdal | >= 0 < 7.7.0+dfsg-3 | 7.7.0+dfsg-3 |
| heimdal_project | heimdal | >= 0 < 7.5.0+dfsg-1ubuntu0.1 | 7.5.0+dfsg-1ubuntu0.1 |
| heimdal_project | heimdal | >= 0 < 7.7.0+dfsg-1ubuntu1.1 | 7.7.0+dfsg-1ubuntu1.1 |
| heimdal_project | heimdal | >= 0 < 1.6~git20131207+dfsg-1ubuntu1.2+esm1 | 1.6~git20131207+dfsg-1ubuntu1.2+esm1 |
| heimdal_project | heimdal | >= 0 < 1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1 | 1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm1 |
| msrc | azl3_samba_4.18.3-1_on_azure_linux_3.0 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| samba | samba | < 4.13.12 | 4.13.12 |
| samba | samba | — | — |
| samba | samba | >= 0 < 2:4.13.13+dfsg-1~deb11u1 | 2:4.13.13+dfsg-1~deb11u1 |
| samba | samba | >= 0 < 2:4.13.13+dfsg-1 | 2:4.13.13+dfsg-1 |
| samba | samba | >= 0 < 2:4.13.13+dfsg-1 | 2:4.13.13+dfsg-1 |
| samba | samba | >= 0 < 2:4.13.13+dfsg-1 | 2:4.13.13+dfsg-1 |
| samba | samba | >= 0 < 2:4.7.6+dfsg~ubuntu-0ubuntu2.27 | 2:4.7.6+dfsg~ubuntu-0ubuntu2.27 |
| samba | samba | >= 0 < 2:4.7.6+dfsg~ubuntu-0ubuntu2.26 | 2:4.7.6+dfsg~ubuntu-0ubuntu2.26 |
| samba | samba | >= 0 < 2:4.13.14+dfsg-0ubuntu0.20.04.4 | 2:4.13.14+dfsg-0ubuntu0.20.04.4 |
| samba | samba | >= 0 < 2:4.13.14+dfsg-0ubuntu0.20.04.3 | 2:4.13.14+dfsg-0ubuntu0.20.04.3 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_debian6.5MEDIUM
vendor_msrc6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Heimdal vulnerabilities
vendor_ubuntu·2022-10-13·CVSS 7.5
CVE-2018-16860 [HIGH] Heimdal vulnerabilities
Title: Heimdal vulnerabilities
Summary: Several security issues were fixed in Heimdal.
Isaac Boukris and Andrew Bartlett discovered that Heimdal's KDC was
not properly performing checksum algorithm verifications in the
S4U2Self extension module. An attacker could possibly use this issue
to perform a machine-in-the-middle attack and request S4U2Self
tickets for any user known by the application. This issue only
affected Ubuntu 14.04 ESM, Ubuntu 16.04 ESM and Ubuntu 18.04 LTS.
(CVE-2018-16860)
It was discovered that Heimdal was not properly handling the
verification of key exchanges when an anonymous PKINIT was being
used. An attacker could possibly use this issue to perform a
machine-in-the-middle attack and expose sensitive information.
This issue only affected Ubuntu 14.04 ESM, Ubuntu
Ubuntu
Samba regression
vendor_ubuntu·2021-12-13·CVSS 5.9
[MEDIUM] Samba regression
Title: Samba regression
Summary: USN-5174-1 introduced a regression in Samba.
USN-5174-1 fixed vulnerabilities in Samba. Some of the changes introduced a
regression in Kerberos authentication in certain environments.
Please see the following upstream bug for more information:
https://bugzilla.samba.org/show_bug.cgi?id=14922
This update fixes the problem.
Original advisory details:
Stefan Metzmacher discovered that Samba incorrectly handled SMB1 client
connections. A remote attacker could possibly use this issue to downgrade
connections to plaintext authentication. (CVE-2016-2124)
Andrew Bartlett discovered that Samba incorrectly mapping domain users to
local users. An authenticated attacker could possibly use this issue to
become root on domain members. (CVE-2020-25717)
Andrew Bart
Ubuntu
Samba regression
vendor_ubuntu·2021-12-13·CVSS 5.9
[MEDIUM] Samba regression
Title: Samba regression
Summary: USN-5142-1 introduced a regression in Samba.
USN-5142-1 fixed vulnerabilities in Samba. Some of the upstream changes
introduced a regression in Kerberos authentication in certain environments.
Please see the following upstream bug for more information:
https://bugzilla.samba.org/show_bug.cgi?id=14922
This update fixes the problem.
Original advisory details:
Stefan Metzmacher discovered that Samba incorrectly handled SMB1 client
connections. A remote attacker could possibly use this issue to downgrade
connections to plaintext authentication. (CVE-2016-2124)
Andrew Bartlett discovered that Samba incorrectly mapping domain users to
local users. An authenticated attacker could possibly use this issue to
become root on domain members. (CVE-2020-25717)
An
Ubuntu
Samba vulnerabilities
vendor_ubuntu·2021-12-06·CVSS 5.9
CVE-2016-2124 [MEDIUM] Samba vulnerabilities
Title: Samba vulnerabilities
Summary: Several security issues were fixed in Samba.
Stefan Metzmacher discovered that Samba incorrectly handled SMB1 client
connections. A remote attacker could possibly use this issue to downgrade
connections to plaintext authentication. (CVE-2016-2124)
Andrew Bartlett discovered that Samba incorrectly mapping domain users to
local users. An authenticated attacker could possibly use this issue to
become root on domain members. (CVE-2020-25717)
Andrew Bartlett discovered that Samba did not properly check sensitive
attributes. An authenticated attacker could possibly use this issue to
escalate privileges. (CVE-2020-25722)
Joseph Sutton discovered that Samba incorrectly handled certain TGS
requests. An authenticated attacker could possibly use this issue t
Ubuntu
Samba regressions
vendor_ubuntu·2021-12-06·CVSS 5.9
[MEDIUM] Samba regressions
Title: Samba regressions
Summary: USN-5142-1 introduced regressions in Samba.
USN-5142-1 fixed vulnerabilities in Samba. Some of the upstream changes
introduced regressions in name mapping and backups.
Please see the following upstream bugs for more information:
https://bugzilla.samba.org/show_bug.cgi?id=14901
https://bugzilla.samba.org/show_bug.cgi?id=14918
This update fixes the problem.
Original advisory details:
Stefan Metzmacher discovered that Samba incorrectly handled SMB1 client
connections. A remote attacker could possibly use this issue to downgrade
connections to plaintext authentication. (CVE-2016-2124)
Andrew Bartlett discovered that Samba incorrectly mapping domain users to
local users. An authenticated attacker could possibly use this issue to
become root on domain mem
Ubuntu
Samba vulnerabilities
vendor_ubuntu·2021-11-11·CVSS 5.9
CVE-2020-25721 [MEDIUM] Samba vulnerabilities
Title: Samba vulnerabilities
Summary: Several security issues were fixed in Samba.
Stefan Metzmacher discovered that Samba incorrectly handled SMB1 client
connections. A remote attacker could possibly use this issue to downgrade
connections to plaintext authentication. (CVE-2016-2124)
Andrew Bartlett discovered that Samba incorrectly mapping domain users to
local users. An authenticated attacker could possibly use this issue to
become root on domain members. (CVE-2020-25717)
Andrew Bartlett discovered that Samba did not correctly sandbox Kerberos
tickets issues by an RODC. An RODC could print administrator tickets,
contrary to expectations. (CVE-2020-25718)
Andrew Bartlett discovered that Samba incorrectly handled Kerberos tickets.
Delegated administrators could possibly use this issu
Microsoft
A null pointer de-reference was found in the way samba kerberos server handled missing sname in TGS-REQ (Ticket Granting Server - Request). An authenticated user could use this flaw to crash the samba
vendor_msrc·2021-10-12·CVSS 6.5
CVE-2021-3671 [MEDIUM] CWE-476 A null pointer de-reference was found in the way samba kerberos server handled missing sname in TGS-REQ (Ticket Granting Server - Request). An authenticated user could use this flaw to crash the samba
A null pointer de-reference was found in the way samba kerberos server handled missing sname in TGS-REQ (Ticket Granting Server - Request). An authenticated user could use this flaw to crash the samba server.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will up
Red Hat
samba: Null pointer dereference on missing sname in TGS-REQ
vendor_redhat·2021-08-31·CVSS 6.5
CVE-2021-3671 [MEDIUM] CWE-476 samba: Null pointer dereference on missing sname in TGS-REQ
samba: Null pointer dereference on missing sname in TGS-REQ
A null pointer de-reference was found in the way samba kerberos server handled missing sname in TGS-REQ (Ticket Granting Server - Request). An authenticated user could use this flaw to crash the samba server.
A null pointer de-reference was found in the way samba kerberos server handled missing sname in TGS-REQ (Ticket Granting Server - Request). An authenticated user could use this flaw to crash the samba server.
Statement: Versions of samba package shipped with Red Hat products do not embed the affected Heimdal code and therefore are not affected by this flaw.
Package: samba (Red Hat Enterprise Linux 7) - Not affected
Package: samba (Red Hat Enterprise Linux 8) - Not affected
Package: samba (Red Hat Enterprise Linux 9) - N
Debian
CVE-2021-3671: heimdal - A null pointer de-reference was found in the way samba kerberos server handled m...
vendor_debian·2021·CVSS 6.5
CVE-2021-3671 [MEDIUM] CVE-2021-3671: heimdal - A null pointer de-reference was found in the way samba kerberos server handled m...
A null pointer de-reference was found in the way samba kerberos server handled missing sname in TGS-REQ (Ticket Granting Server - Request). An authenticated user could use this flaw to crash the samba server.
Scope: local
bookworm: resolved (fixed in 7.7.0+dfsg-3)
bullseye: resolved (fixed in 7.7.0+dfsg-2+deb11u2)
forky: resolved (fixed in 7.7.0+dfsg-3)
sid: resolved (fixed in 7.7.0+dfsg-3)
trixie: resolved (fixed in 7.7.0+dfsg-3)
OSV
heimdal vulnerabilities
osv·2022-10-13·CVSS 7.5
CVE-2018-16860 [HIGH] heimdal vulnerabilities
heimdal vulnerabilities
Isaac Boukris and Andrew Bartlett discovered that Heimdal's KDC was
not properly performing checksum algorithm verifications in the
S4U2Self extension module. An attacker could possibly use this issue
to perform a machine-in-the-middle attack and request S4U2Self
tickets for any user known by the application. This issue only
affected Ubuntu 14.04 ESM, Ubuntu 16.04 ESM and Ubuntu 18.04 LTS.
(CVE-2018-16860)
It was discovered that Heimdal was not properly handling the
verification of key exchanges when an anonymous PKINIT was being
used. An attacker could possibly use this issue to perform a
machine-in-the-middle attack and expose sensitive information.
This issue only affected Ubuntu 14.04 ESM, Ubuntu 16.04 ESM and
Ubuntu 18.04 LTS. (CVE-2019-12098)
Joseph Sutton
GHSA
GHSA-ghqf-jx44-h9c5: A null pointer de-reference was found in the way samba kerberos server handled missing sname in TGS-REQ (Ticket Granting Server - Request)
ghsa_unreviewed·2022-05-24
CVE-2021-3671 [MEDIUM] CWE-476 GHSA-ghqf-jx44-h9c5: A null pointer de-reference was found in the way samba kerberos server handled missing sname in TGS-REQ (Ticket Granting Server - Request)
A null pointer de-reference was found in the way samba kerberos server handled missing sname in TGS-REQ (Ticket Granting Server - Request). An authenticated user could use this flaw to crash the samba server.
OSV
samba regression
osv·2021-12-13·CVSS 5.9
[MEDIUM] samba regression
samba regression
USN-5142-1 fixed vulnerabilities in Samba. Some of the upstream changes
introduced a regression in Kerberos authentication in certain environments.
Please see the following upstream bug for more information:
https://bugzilla.samba.org/show_bug.cgi?id=14922
This update fixes the problem.
Original advisory details:
Stefan Metzmacher discovered that Samba incorrectly handled SMB1 client
connections. A remote attacker could possibly use this issue to downgrade
connections to plaintext authentication. (CVE-2016-2124)
Andrew Bartlett discovered that Samba incorrectly mapping domain users to
local users. An authenticated attacker could possibly use this issue to
become root on domain members. (CVE-2020-25717)
Andrew Bartlett discovered that Samba did not correctly sandbox
OSV
samba regression
osv·2021-12-13·CVSS 5.9
[MEDIUM] samba regression
samba regression
USN-5174-1 fixed vulnerabilities in Samba. Some of the changes introduced a
regression in Kerberos authentication in certain environments.
Please see the following upstream bug for more information:
https://bugzilla.samba.org/show_bug.cgi?id=14922
This update fixes the problem.
Original advisory details:
Stefan Metzmacher discovered that Samba incorrectly handled SMB1 client
connections. A remote attacker could possibly use this issue to downgrade
connections to plaintext authentication. (CVE-2016-2124)
Andrew Bartlett discovered that Samba incorrectly mapping domain users to
local users. An authenticated attacker could possibly use this issue to
become root on domain members. (CVE-2020-25717)
Andrew Bartlett discovered that Samba did not properly check sensitive
at
OSV
samba vulnerabilities
osv·2021-12-06·CVSS 5.9
CVE-2016-2124 [MEDIUM] samba vulnerabilities
samba vulnerabilities
Stefan Metzmacher discovered that Samba incorrectly handled SMB1 client
connections. A remote attacker could possibly use this issue to downgrade
connections to plaintext authentication. (CVE-2016-2124)
Andrew Bartlett discovered that Samba incorrectly mapping domain users to
local users. An authenticated attacker could possibly use this issue to
become root on domain members. (CVE-2020-25717)
Andrew Bartlett discovered that Samba did not properly check sensitive
attributes. An authenticated attacker could possibly use this issue to
escalate privileges. (CVE-2020-25722)
Joseph Sutton discovered that Samba incorrectly handled certain TGS
requests. An authenticated attacker could possibly use this issue to cause
Samba to crash, resulting in a denial of service. (CVE
OSV
samba regressions
osv·2021-12-06·CVSS 5.9
[MEDIUM] samba regressions
samba regressions
USN-5142-1 fixed vulnerabilities in Samba. Some of the upstream changes
introduced regressions in name mapping and backups.
Please see the following upstream bugs for more information:
https://bugzilla.samba.org/show_bug.cgi?id=14901
https://bugzilla.samba.org/show_bug.cgi?id=14918
This update fixes the problem.
Original advisory details:
Stefan Metzmacher discovered that Samba incorrectly handled SMB1 client
connections. A remote attacker could possibly use this issue to downgrade
connections to plaintext authentication. (CVE-2016-2124)
Andrew Bartlett discovered that Samba incorrectly mapping domain users to
local users. An authenticated attacker could possibly use this issue to
become root on domain members. (CVE-2020-25717)
Andrew Bartlett discovered that Samba
OSV
samba vulnerabilities
osv·2021-11-11·CVSS 5.9
CVE-2016-2124 [MEDIUM] samba vulnerabilities
samba vulnerabilities
Stefan Metzmacher discovered that Samba incorrectly handled SMB1 client
connections. A remote attacker could possibly use this issue to downgrade
connections to plaintext authentication. (CVE-2016-2124)
Andrew Bartlett discovered that Samba incorrectly mapping domain users to
local users. An authenticated attacker could possibly use this issue to
become root on domain members. (CVE-2020-25717)
Andrew Bartlett discovered that Samba did not correctly sandbox Kerberos
tickets issues by an RODC. An RODC could print administrator tickets,
contrary to expectations. (CVE-2020-25718)
Andrew Bartlett discovered that Samba incorrectly handled Kerberos tickets.
Delegated administrators could possibly use this issue to impersonate
accounts, leading to total domain compromise.
OSV
CVE-2021-3671: A null pointer de-reference was found in the way samba kerberos server handled missing sname in TGS-REQ (Ticket Granting Server - Request)
osv·2021-10-12·CVSS 6.5
CVE-2021-3671 [MEDIUM] CVE-2021-3671: A null pointer de-reference was found in the way samba kerberos server handled missing sname in TGS-REQ (Ticket Granting Server - Request)
A null pointer de-reference was found in the way samba kerberos server handled missing sname in TGS-REQ (Ticket Granting Server - Request). An authenticated user could use this flaw to crash the samba server.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.redhat.com/show_bug.cgi?id=2013080%2Chttps://bugzilla.samba.org/show_bug.cgi?id=14770%2Chttps://github.com/heimdal/heimdal/commit/04171147948d0a3636bc6374181926f0fb2ec83ahttps://lists.debian.org/debian-lts-announce/2022/11/msg00034.htmlhttps://security.netapp.com/advisory/ntap-20221215-0002/https://security.netapp.com/advisory/ntap-20230216-0008/https://www.debian.org/security/2022/dsa-5287https://bugzilla.redhat.com/show_bug.cgi?id=2013080%2Chttps://bugzilla.samba.org/show_bug.cgi?id=14770%2Chttps://github.com/heimdal/heimdal/commit/04171147948d0a3636bc6374181926f0fb2ec83ahttps://lists.debian.org/debian-lts-announce/2022/11/msg00034.htmlhttps://security.netapp.com/advisory/ntap-20221215-0002/https://security.netapp.com/advisory/ntap-20230216-0008/https://www.debian.org/security/2022/dsa-5287
2021-10-12
Published