cbcvebase.
CVE-2021-44142
published 2022-02-21

CVE-2021-44142: The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "...enhanced compatibility with Apple SMB clients and interoperability with a…

PriorityP190high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
ITWEXPLOITVulnCheck KEVInitial access
Exploited in the wild
EPSS
73.72%
99.4th percentile
The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "...enhanced compatibility with Apple SMB clients and interoperability with a Netatalk 3 AFP fileserver." Samba versions prior to 4.13.17, 4.14.12 and 4.15.5 with vfs_fruit configured allow out-of-bounds heap read and write via specially crafted extended file attributes. A remote attacker with write access to extended file attributes can execute arbitrary code with the privileges of smbd, typically root.

Affected

58 ranges· showing 25
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiandebian_linux
debiansamba< samba 2:4.16.0+dfsg-2 (bookworm)samba 2:4.16.0+dfsg-2 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
msrcazl3_samba_4.18.3-1_on_azure_linux_3.0
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64
paloaltopan-os
paloaltoprisma_access
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_linux_desktop
redhatenterprise_linux_eus
redhatenterprise_linux_eus
redhatenterprise_linux_for_ibm_z_systems
redhatenterprise_linux_for_ibm_z_systems
redhatenterprise_linux_for_ibm_z_systems_eus
redhatenterprise_linux_for_ibm_z_systems_eus
redhatenterprise_linux_for_power_big_endian

Detection & IOCsextracted from sources · hover to see the quote

  • The vulnerability exists in the parsing of EA metadata in the server daemon smbd when opening a file; monitor smbd process for anomalous out-of-bounds memory access triggered via extended file attributes (xattr) on shares with vfs_fruit enabled
  • Exploitation vector is via specially crafted extended file attributes (EA/xattr); any remote write to xattrs on a Samba share with vfs_fruit configured should be treated as a high-risk event and monitored
  • Monitor for smbd running as root executing unexpected child processes or spawning shells, as successful exploitation grants arbitrary code execution with root privileges
  • Audit Samba share configurations for presence of vfs_fruit in vfs objects lines; installations NOT using vfs_fruit are unaffected — focus detection on hosts where fruit VFS module is active
  • NAS devices are a high-priority detection/patching target as they commonly ship with older smbd versions (e.g. 4.9.5) and vfs_fruit enabled by default for Apple interoperability
  • ·Only Samba installations with the vfs_fruit VFS module configured are vulnerable; default configurations without vfs_fruit are not affected
  • ·Affected Samba versions are all releases prior to 4.13.17, 4.14.12, and 4.15.5; patched releases are 4.13.17, 4.14.12, and 4.15.5
  • ·Removing the fruit VFS module from vfs objects lines is a vendor-suggested workaround but can severely impact macOS clients accessing the server

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
osv8.8HIGH
vulncheck8.8HIGH
vendor_debian8.8HIGH
vendor_msrc8.8HIGH
vendor_redhat8.8HIGH
vendor_ubuntu8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.