CVE-2023-34966
published 2023-07-20CVE-2023-34966: An infinite loop vulnerability was found in Samba's mdssvc RPC service for Spotlight. When parsing Spotlight mdssvc RPC packets sent by the client, the core…
PriorityP260high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
60.33%
99.0th percentile
An infinite loop vulnerability was found in Samba's mdssvc RPC service for Spotlight. When parsing Spotlight mdssvc RPC packets sent by the client, the core unmarshalling function sl_unpack_loop() did not validate a field in the network packet that contains the count of elements in an array-like structure. By passing 0 as the count value, the attacked function will run in an endless loop consuming 100% CPU. This flaw allows an attacker to issue a malformed RPC request, triggering an infinite loop, resulting in a denial of service condition.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | samba | < samba 2:4.17.10+dfsg-0+deb12u1 (bookworm) | samba 2:4.17.10+dfsg-0+deb12u1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| samba | samba | < 4.16.11 | 4.16.11 |
| samba | samba | >= 0 < 2:4.13.13+dfsg-1~deb11u6 | 2:4.13.13+dfsg-1~deb11u6 |
| samba | samba | >= 0 < 2:4.17.10+dfsg-0+deb12u1 | 2:4.17.10+dfsg-0+deb12u1 |
| samba | samba | >= 0 < 2:4.18.5+dfsg-1 | 2:4.18.5+dfsg-1 |
| samba | samba | >= 0 < 2:4.18.5+dfsg-1 | 2:4.18.5+dfsg-1 |
| samba | samba | >= 0 < 2:4.15.13+dfsg-0ubuntu0.20.04.3 | 2:4.15.13+dfsg-0ubuntu0.20.04.3 |
| samba | samba | >= 0 < 2:4.15.13+dfsg-0ubuntu1.2 | 2:4.15.13+dfsg-0ubuntu1.2 |
| samba | samba | >= 0 < 2:4.3.11+dfsg-0ubuntu0.14.04.20+esm13 | 2:4.3.11+dfsg-0ubuntu0.14.04.20+esm13 |
| samba | samba | >= 0 < 2:4.3.11+dfsg-0ubuntu0.14.04.20+esm14 | 2:4.3.11+dfsg-0ubuntu0.14.04.20+esm14 |
| samba | samba | >= 0 < 2:4.3.11+dfsg-0ubuntu0.16.04.34+esm2 | 2:4.3.11+dfsg-0ubuntu0.16.04.34+esm2 |
| samba | samba | >= 0 < 2:4.3.11+dfsg-0ubuntu0.16.04.34+esm3 | 2:4.3.11+dfsg-0ubuntu0.16.04.34+esm3 |
| samba | samba | >= 0 < 2:4.7.6+dfsg~ubuntu-0ubuntu2.29+esm1 | 2:4.7.6+dfsg~ubuntu-0ubuntu2.29+esm1 |
| samba | samba | >= 0 < 2:4.7.6+dfsg~ubuntu-0ubuntu2.29+esm2 | 2:4.7.6+dfsg~ubuntu-0ubuntu2.29+esm2 |
| samba | samba | >= 4.17.0 < 4.17.10 | 4.17.10 |
| samba | samba | >= 4.18.0 < 4.18.5 | 4.18.5 |
Detection & IOCsextracted from sources · hover to see the quote
- →Target the mdssvc RPC service (Spotlight) in Samba — malformed RPC packets with a count value of 0 in an array-like structure field trigger an infinite loop in sl_unpack_loop(), causing 100% CPU consumption (DoS). ↗
- →Monitor Samba processes for sustained 100% CPU usage on systems where Spotlight is enabled, which may indicate exploitation of this infinite loop vulnerability. ↗
- ·This vulnerability only affects Samba servers where Spotlight is explicitly enabled. The default configuration has Spotlight disabled. Mitigation is to remove all 'spotlight=yes|true' configuration stanzas. ↗
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Samba regression
vendor_ubuntu·2025-06-30·CVSS 6.5
CVE-2022-3437 [MEDIUM] Samba regression
Title: Samba regression
Summary: USN-7582-1 introduced a regression in Samba.
USN-7582-1 fixed vulnerabilities in Samba. The update introduced a
regression. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Evgeny Legerov discovered that Samba incorrectly handled buffers in
certain GSSAPI routines of Heimdal. A remote attacker could possibly use
this issue to cause Samba to crash, resulting in a denial of service.
(CVE-2022-3437)
Greg Hudson discovered that Samba incorrectly handled PAC parsing. On
32-bit systems, a remote attacker could use this issue to escalate
privileges, or possibly execute arbitrary code. (CVE-2022-42898)
Joseph Sutton discovered that Samba could be forced to issue rc4-hmac
encrypted Kerberos tickets. A remote attack
Ubuntu
Samba vulnerabilities
vendor_ubuntu·2025-06-19·CVSS 6.5
CVE-2023-34966 [MEDIUM] Samba vulnerabilities
Title: Samba vulnerabilities
Summary: Several security issues were fixed in Samba.
Evgeny Legerov discovered that Samba incorrectly handled buffers in
certain GSSAPI routines of Heimdal. A remote attacker could possibly use
this issue to cause Samba to crash, resulting in a denial of service.
(CVE-2022-3437)
Greg Hudson discovered that Samba incorrectly handled PAC parsing. On
32-bit systems, a remote attacker could use this issue to escalate
privileges, or possibly execute arbitrary code. (CVE-2022-42898)
Joseph Sutton discovered that Samba could be forced to issue rc4-hmac
encrypted Kerberos tickets. A remote attacker could possibly use this issue
to escalate privileges. This issue only affected Ubuntu 20.04 LTS and
Ubuntu 22.04 LTS. (CVE-2022-45141)
Florent Saudel discovered that S
Ubuntu
Samba vulnerabilities
vendor_ubuntu·2023-07-19·CVSS 5.9
CVE-2023-3347 [MEDIUM] Samba vulnerabilities
Title: Samba vulnerabilities
Summary: Several security issues were fixed in Samba.
It was discovered that Samba incorrectly handled Winbind NTLM
authentication responses. An attacker could possibly use this issue to
cause Samba to crash, resulting in a denial of service. (CVE-2022-2127)
Andreas Schneider discovered that Samba incorrectly enforced SMB2 packet
signing. A remote attacker could possibly use this issue to obtain or
modify sensitive information. This issue only affected Ubuntu 23.04.
(CVE-2023-3347)
Florent Saudel and Arnaud Gatignolof discovered that Samba incorrectly
handled certain Spotlight requests. A remote attacker could possibly use
this issue to cause Samba to consume resources, leading to a denial of
service. (CVE-2023-34966, CVE-2023-34967)
Ralph Boehme and Stefa
Red Hat
samba: infinite loop in mdssvc RPC service for spotlight
vendor_redhat·2023-07-19·CVSS 7.5
CVE-2023-34966 [HIGH] CWE-835 samba: infinite loop in mdssvc RPC service for spotlight
samba: infinite loop in mdssvc RPC service for spotlight
An infinite loop vulnerability was found in Samba's mdssvc RPC service for Spotlight. When parsing Spotlight mdssvc RPC packets sent by the client, the core unmarshalling function sl_unpack_loop() did not validate a field in the network packet that contains the count of elements in an array-like structure. By passing 0 as the count value, the attacked function will run in an endless loop consuming 100% CPU. This flaw allows an attacker to issue a malformed RPC request, triggering an infinite loop, resulting in a denial of service condition.
An infinite loop vulnerability was found in Samba's mdssvc RPC service for Spotlight. When parsing Spotlight mdssvc RPC packets sent by the client, the core unmarshalling function sl_unpack_loop
Debian
CVE-2023-34966: samba - An infinite loop vulnerability was found in Samba's mdssvc RPC service for Spotl...
vendor_debian·2023·CVSS 7.5
CVE-2023-34966 [HIGH] CVE-2023-34966: samba - An infinite loop vulnerability was found in Samba's mdssvc RPC service for Spotl...
An infinite loop vulnerability was found in Samba's mdssvc RPC service for Spotlight. When parsing Spotlight mdssvc RPC packets sent by the client, the core unmarshalling function sl_unpack_loop() did not validate a field in the network packet that contains the count of elements in an array-like structure. By passing 0 as the count value, the attacked function will run in an endless loop consuming 100% CPU. This flaw allows an attacker to issue a malformed RPC request, triggering an infinite loop, resulting in a denial of service condition.
Scope: local
bookworm: resolved (fixed in 2:4.17.10+dfsg-0+deb12u1)
bullseye: resolved (fixed in 2:4.13.13+dfsg-1~deb11u6)
forky: resolved (fixed in 2:4.18.5+dfsg-1)
sid: resolved (fixed in 2:4.18.5+dfsg-1)
trixie: resolved (fixed in 2:4.18.5+dfsg-1)
OSV
samba regression
osv·2025-06-30·CVSS 6.5
CVE-2022-3437 [MEDIUM] samba regression
samba regression
USN-7582-1 fixed vulnerabilities in Samba. The update introduced a
regression. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Evgeny Legerov discovered that Samba incorrectly handled buffers in
certain GSSAPI routines of Heimdal. A remote attacker could possibly use
this issue to cause Samba to crash, resulting in a denial of service.
(CVE-2022-3437)
Greg Hudson discovered that Samba incorrectly handled PAC parsing. On
32-bit systems, a remote attacker could use this issue to escalate
privileges, or possibly execute arbitrary code. (CVE-2022-42898)
Joseph Sutton discovered that Samba could be forced to issue rc4-hmac
encrypted Kerberos tickets. A remote attacker could possibly use this
issue to escalate privileges. This
OSV
samba vulnerabilities
osv·2025-06-19·CVSS 6.5
CVE-2022-3437 [MEDIUM] samba vulnerabilities
samba vulnerabilities
Evgeny Legerov discovered that Samba incorrectly handled buffers in
certain GSSAPI routines of Heimdal. A remote attacker could possibly use
this issue to cause Samba to crash, resulting in a denial of service.
(CVE-2022-3437)
Greg Hudson discovered that Samba incorrectly handled PAC parsing. On
32-bit systems, a remote attacker could use this issue to escalate
privileges, or possibly execute arbitrary code. (CVE-2022-42898)
Joseph Sutton discovered that Samba could be forced to issue rc4-hmac
encrypted Kerberos tickets. A remote attacker could possibly use this issue
to escalate privileges. This issue only affected Ubuntu 20.04 LTS and
Ubuntu 22.04 LTS. (CVE-2022-45141)
Florent Saudel discovered that Samba incorrectly handled certain Spotlight
requests. A remote
GHSA
GHSA-45c7-642q-qm9m: An infinite loop vulnerability was found in Samba's mdssvc RPC service for Spotlight
ghsa_unreviewed·2023-07-20
CVE-2023-34966 [HIGH] CWE-835 GHSA-45c7-642q-qm9m: An infinite loop vulnerability was found in Samba's mdssvc RPC service for Spotlight
An infinite loop vulnerability was found in Samba's mdssvc RPC service for Spotlight. When parsing Spotlight mdssvc RPC packets sent by the client, the core unmarshalling function sl_unpack_loop() did not validate a field in the network packet that contains the count of elements in an array-like structure. By passing 0 as the count value, the attacked function will run in an endless loop consuming 100% CPU. This flaw allows an attacker to issue a malformed RPC request, triggering an infinite loop, resulting in a denial of service condition.
OSV
CVE-2023-34966: An infinite loop vulnerability was found in Samba's mdssvc RPC service for Spotlight
osv·2023-07-20·CVSS 7.5
CVE-2023-34966 [HIGH] CVE-2023-34966: An infinite loop vulnerability was found in Samba's mdssvc RPC service for Spotlight
An infinite loop vulnerability was found in Samba's mdssvc RPC service for Spotlight. When parsing Spotlight mdssvc RPC packets sent by the client, the core unmarshalling function sl_unpack_loop() did not validate a field in the network packet that contains the count of elements in an array-like structure. By passing 0 as the count value, the attacked function will run in an endless loop consuming 100% CPU. This flaw allows an attacker to issue a malformed RPC request, triggering an infinite loop, resulting in a denial of service condition.
OSV
samba vulnerabilities
osv·2023-07-19·CVSS 5.9
CVE-2022-2127 [MEDIUM] samba vulnerabilities
samba vulnerabilities
It was discovered that Samba incorrectly handled Winbind NTLM
authentication responses. An attacker could possibly use this issue to
cause Samba to crash, resulting in a denial of service. (CVE-2022-2127)
Andreas Schneider discovered that Samba incorrectly enforced SMB2 packet
signing. A remote attacker could possibly use this issue to obtain or
modify sensitive information. This issue only affected Ubuntu 23.04.
(CVE-2023-3347)
Florent Saudel and Arnaud Gatignolof discovered that Samba incorrectly
handled certain Spotlight requests. A remote attacker could possibly use
this issue to cause Samba to consume resources, leading to a denial of
service. (CVE-2023-34966, CVE-2023-34967)
Ralph Boehme and Stefan Metzmacher discovered that Samba incorrectly
handled paths r
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/errata/RHSA-2023:6667https://access.redhat.com/errata/RHSA-2023:7139https://access.redhat.com/errata/RHSA-2024:0423https://access.redhat.com/errata/RHSA-2024:0580https://access.redhat.com/errata/RHSA-2024:4101https://access.redhat.com/security/cve/CVE-2023-34966https://bugzilla.redhat.com/show_bug.cgi?id=2222793https://www.samba.org/samba/security/CVE-2023-34966https://access.redhat.com/errata/RHSA-2023:6667https://access.redhat.com/errata/RHSA-2023:7139https://access.redhat.com/errata/RHSA-2024:0423https://access.redhat.com/errata/RHSA-2024:0580https://access.redhat.com/errata/RHSA-2024:4101https://access.redhat.com/security/cve/CVE-2023-34966https://bugzilla.redhat.com/show_bug.cgi?id=2222793https://lists.fedoraproject.org/archives/list/[email protected]/message/BPCSGND7LO467AJGR5DYBGZLTCGTOBCC/https://lists.fedoraproject.org/archives/list/[email protected]/message/OT74M42E6C36W7PQVY3OS4ZM7DVYB64Z/https://security.netapp.com/advisory/ntap-20230731-0010/https://www.debian.org/security/2023/dsa-5477https://www.samba.org/samba/security/CVE-2023-34966
2023-07-20
Published