CVE-2021-43566
published 2022-01-11CVE-2021-43566: All versions of Samba prior to 4.13.16 are vulnerable to a malicious client using an SMB1 or NFS race to allow a directory to be created in an area of the…
PriorityP410low2.5CVSS 3.1
AVLACHPRLUINSUCNILAN
EPSS
0.38%
30.2th percentile
All versions of Samba prior to 4.13.16 are vulnerable to a malicious client using an SMB1 or NFS race to allow a directory to be created in an area of the server file system not exported under the share definition. Note that SMB1 has to be enabled, or the share also available via NFS in order for this attack to succeed.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | samba | < samba 2:4.16.0+dfsg-2 (bookworm) | samba 2:4.16.0+dfsg-2 (bookworm) |
| msrc | azl3_samba_4.18.3-1_on_azure_linux_3.0 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| samba | samba | < 4.13.16 | 4.13.16 |
| samba | samba | >= 0 < 2:4.13.13+dfsg-1~deb11u4 | 2:4.13.13+dfsg-1~deb11u4 |
| samba | samba | >= 0 < 2:4.16.0+dfsg-2 | 2:4.16.0+dfsg-2 |
| samba | samba | >= 0 < 2:4.16.0+dfsg-2 | 2:4.16.0+dfsg-2 |
| samba | samba | >= 0 < 2:4.16.0+dfsg-2 | 2:4.16.0+dfsg-2 |
| samba | samba | >= 0 < 2:4.13.17~dfsg-0ubuntu0.21.04.1 | 2:4.13.17~dfsg-0ubuntu0.21.04.1 |
CVSS provenance
nvdv3.12.5LOWCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
nvdv2.01.2LOWAV:L/AC:H/Au:N/C:N/I:P/A:N
osv2.5LOW
vendor_debian2.5LOW
vendor_msrc2.5LOW
vendor_redhat2.5LOW
vendor_ubuntu2.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
samba vulnerabilities
osv·2022-02-01·CVSS 2.5
CVE-2021-44142 [LOW] samba vulnerabilities
samba vulnerabilities
Orange Tsai discovered that the Samba vfs_fruit module incorrectly handled
certain memory operations. A remote attacker could use this issue to cause
Samba to crash, resulting in a denial of service, or possibly execute
arbitrary code as root. (CVE-2021-44142)
Michael Hanselmann discovered that Samba incorrectly created directories.
In certain configurations, a remote attacker could possibly create a
directory on the server outside of the shared directory. (CVE-2021-43566)
Kees van Vloten discovered that Samba incorrectly handled certain aliased
SPN checks. A remote attacker could possibly use this issue to impersonate
services. (CVE-2022-0336)
GHSA
GHSA-rcx2-p86p-53w9: All versions of Samba prior to 4
ghsa_unreviewed·2022-01-12
CVE-2021-43566 [LOW] CWE-362 GHSA-rcx2-p86p-53w9: All versions of Samba prior to 4
All versions of Samba prior to 4.13.16 are vulnerable to a malicious client using an SMB1 or NFS race to allow a directory to be created in an area of the server file system not exported under the share definition. Note that SMB1 has to be enabled, or the share also available via NFS in order for this attack to succeed.
OSV
CVE-2021-43566: All versions of Samba prior to 4
osv·2022-01-11·CVSS 2.5
CVE-2021-43566 [LOW] CVE-2021-43566: All versions of Samba prior to 4
All versions of Samba prior to 4.13.16 are vulnerable to a malicious client using an SMB1 or NFS race to allow a directory to be created in an area of the server file system not exported under the share definition. Note that SMB1 has to be enabled, or the share also available via NFS in order for this attack to succeed.
Ubuntu
Samba vulnerabilities
vendor_ubuntu·2022-02-01·CVSS 2.5
CVE-2022-0336 [LOW] Samba vulnerabilities
Title: Samba vulnerabilities
Summary: Several security issues were fixed in Samba.
Orange Tsai discovered that the Samba vfs_fruit module incorrectly handled
certain memory operations. A remote attacker could use this issue to cause
Samba to crash, resulting in a denial of service, or possibly execute
arbitrary code as root. (CVE-2021-44142)
Michael Hanselmann discovered that Samba incorrectly created directories.
In certain configurations, a remote attacker could possibly create a
directory on the server outside of the shared directory. (CVE-2021-43566)
Kees van Vloten discovered that Samba incorrectly handled certain aliased
SPN checks. A remote attacker could possibly use this issue to impersonate
services. (CVE-2022-0336)
Instructions: This update uses a new upstream release, whic
Microsoft
All versions of Samba prior to 4.13.16 are vulnerable to a malicious client using an SMB1 or NFS race to allow a directory to be created in an area of the server file system not exported under the sha
vendor_msrc·2022-01-11·CVSS 2.5
CVE-2021-43566 [LOW] CWE-362 All versions of Samba prior to 4.13.16 are vulnerable to a malicious client using an SMB1 or NFS race to allow a directory to be created in an area of the server file system not exported under the sha
All versions of Samba prior to 4.13.16 are vulnerable to a malicious client using an SMB1 or NFS race to allow a directory to be created in an area of the server file system not exported under the share definition. Note that SMB1 has to be enabled or the share also available via NFS in order for this attack to succeed.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in O
Red Hat
samba: Symlink race error can allow directory creation outside of the exported share
vendor_redhat·2022-01-10·CVSS 2.5
CVE-2021-43566 [LOW] CWE-362 samba: Symlink race error can allow directory creation outside of the exported share
samba: Symlink race error can allow directory creation outside of the exported share
All versions of Samba prior to 4.13.16 are vulnerable to a malicious client using an SMB1 or NFS race to allow a directory to be created in an area of the server file system not exported under the share definition. Note that SMB1 has to be enabled, or the share also available via NFS in order for this attack to succeed.
Mitigation: Do not enable SMB1 (please note SMB1 is disabled by default in Samba from version 4.11.0 and onwards). This prevents the creation of symbolic links via SMB1. If SMB1 must be enabled for backwards compatibility then add the parameter:
unix extensions = no
to the [global] section of your smb.conf and restart smbd. This prevents SMB1 clients from creating symlinks on the exported
Debian
CVE-2021-43566: samba - All versions of Samba prior to 4.13.16 are vulnerable to a malicious client usin...
vendor_debian·2021·CVSS 2.5
CVE-2021-43566 [LOW] CVE-2021-43566: samba - All versions of Samba prior to 4.13.16 are vulnerable to a malicious client usin...
All versions of Samba prior to 4.13.16 are vulnerable to a malicious client using an SMB1 or NFS race to allow a directory to be created in an area of the server file system not exported under the share definition. Note that SMB1 has to be enabled, or the share also available via NFS in order for this attack to succeed.
Scope: local
bookworm: resolved (fixed in 2:4.16.0+dfsg-2)
bullseye: resolved (fixed in 2:4.13.13+dfsg-1~deb11u4)
forky: resolved (fixed in 2:4.16.0+dfsg-2)
sid: resolved (fixed in 2:4.16.0+dfsg-2)
trixie: resolved (fixed in 2:4.16.0+dfsg-2)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.samba.org/show_bug.cgi?id=13979https://security.netapp.com/advisory/ntap-20220110-0001/https://www.samba.org/samba/security/CVE-2021-43566.htmlhttps://bugzilla.samba.org/show_bug.cgi?id=13979https://security.netapp.com/advisory/ntap-20220110-0001/https://www.samba.org/samba/security/CVE-2021-43566.html
2022-01-11
Published