CVE-2023-42670
published 2023-11-03CVE-2023-42670: A flaw was found in Samba. It is susceptible to a vulnerability where multiple incompatible RPC listeners can be initiated, causing disruptions in the AD DC…
PriorityP434medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
1.10%
62.3th percentile
A flaw was found in Samba. It is susceptible to a vulnerability where multiple incompatible RPC listeners can be initiated, causing disruptions in the AD DC service. When Samba's RPC server experiences a high load or unresponsiveness, servers intended for non-AD DC purposes (for example, NT4-emulation "classic DCs") can erroneously start and compete for the same unix domain sockets. This issue leads to partial query responses from the AD DC, causing issues such as "The procedure number is out of range" when using tools like Active Directory Users. This flaw allows an attacker to disrupt AD DC services.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | samba | < samba 2:4.17.12+dfsg-0+deb12u1 (bookworm) | samba 2:4.17.12+dfsg-0+deb12u1 (bookworm) |
| fedoraproject | fedora | — | — |
| samba | samba | < 4.17.12 | 4.17.12 |
| samba | samba | >= 0 < 2:4.17.12+dfsg-0+deb12u1 | 2:4.17.12+dfsg-0+deb12u1 |
| samba | samba | >= 0 < 2:4.19.1+dfsg-1 | 2:4.19.1+dfsg-1 |
| samba | samba | >= 0 < 2:4.19.1+dfsg-1 | 2:4.19.1+dfsg-1 |
| samba | samba | >= 0 < 2:4.15.13+dfsg-0ubuntu0.20.04.7 | 2:4.15.13+dfsg-0ubuntu0.20.04.7 |
| samba | samba | >= 0 < 2:4.15.13+dfsg-0ubuntu0.20.04.6 | 2:4.15.13+dfsg-0ubuntu0.20.04.6 |
| samba | samba | >= 0 < 2:4.15.13+dfsg-0ubuntu1.5 | 2:4.15.13+dfsg-0ubuntu1.5 |
| samba | samba | >= 0 < 2:4.18.6+dfsg-1ubuntu2.1 | 2:4.18.6+dfsg-1ubuntu2.1 |
| samba | samba | >= 4.18.0 < 4.18.8 | 4.18.8 |
| samba | samba | >= 4.19.0 < 4.19.1 | 4.19.1 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_oracle6.5MEDIUM
vendor_redhat6.5MEDIUM
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2023-42670: A flaw was found in Samba
osv·2023-11-03·CVSS 6.5
CVE-2023-42670 [MEDIUM] CVE-2023-42670: A flaw was found in Samba
A flaw was found in Samba. It is susceptible to a vulnerability where multiple incompatible RPC listeners can be initiated, causing disruptions in the AD DC service. When Samba's RPC server experiences a high load or unresponsiveness, servers intended for non-AD DC purposes (for example, NT4-emulation "classic DCs") can erroneously start and compete for the same unix domain sockets. This issue leads to partial query responses from the AD DC, causing issues such as "The procedure number is out of range" when using tools like Active Directory Users. This flaw allows an attacker to disrupt AD DC services.
GHSA
GHSA-5qvm-gfmw-9v64: A flaw was found in Samba
ghsa_unreviewed·2023-11-03
CVE-2023-42670 [MEDIUM] CWE-400 GHSA-5qvm-gfmw-9v64: A flaw was found in Samba
A flaw was found in Samba. It is susceptible to a vulnerability where multiple incompatible RPC listeners can be initiated, causing disruptions in the AD DC service. When Samba's RPC server experiences a high load or unresponsiveness, servers intended for non-AD DC purposes (for example, NT4-emulation "classic DCs") can erroneously start and compete for the same unix domain sockets. This issue leads to partial query responses from the AD DC, causing issues such as "The procedure number is out of range" when using tools like Active Directory Users. This flaw allows an attacker to disrupt AD DC services.
OSV
samba vulnerabilities
osv·2023-10-17·CVSS 6.5
CVE-2023-4091 [MEDIUM] samba vulnerabilities
samba vulnerabilities
USN-6425-1 fixed vulnerabilities in Samba. This update provides the
corresponding updates for Ubuntu 23.10.
Original advisory details:
Sri Nagasubramanian discovered that the Samba acl_xattr VFS module
incorrectly handled read-only files. When Samba is configured to ignore
system ACLs, a remote attacker could possibly use this issue to truncate
read-only files. (CVE-2023-4091)
Andrew Bartlett discovered that Samba incorrectly handled the DirSync
control. A remote attacker with an RODC DC account could possibly use this
issue to obtain all domain secrets. (CVE-2023-4154)
Andrew Bartlett discovered that Samba incorrectly handled the rpcecho
development server. A remote attacker could possibly use this issue to
cause Samba to stop responding, resulting in a denial o
OSV
samba regression
osv·2023-10-11·CVSS 6.5
[MEDIUM] samba regression
samba regression
USN-6425-1 fixed vulnerabilities in Samba. Due to a build issue on Ubuntu
20.04 LTS, the update introduced regressions in macro handling and
possibly other functionality.
This update fixes the problem. We apologize for the inconvenience.
Original advisory details:
Sri Nagasubramanian discovered that the Samba acl_xattr VFS module
incorrectly handled read-only files. When Samba is configured to ignore
system ACLs, a remote attacker could possibly use this issue to truncate
read-only files. (CVE-2023-4091)
Andrew Bartlett discovered that Samba incorrectly handled the DirSync
control. A remote attacker with an RODC DC account could possibly use this
issue to obtain all domain secrets. (CVE-2023-4154)
Andrew Bartlett discovered that Samba incorrectly handled the rpcecho
OSV
samba vulnerabilities
osv·2023-10-10·CVSS 6.5
CVE-2023-4091 [MEDIUM] samba vulnerabilities
samba vulnerabilities
Sri Nagasubramanian discovered that the Samba acl_xattr VFS module
incorrectly handled read-only files. When Samba is configured to ignore
system ACLs, a remote attacker could possibly use this issue to truncate
read-only files. (CVE-2023-4091)
Andrew Bartlett discovered that Samba incorrectly handled the DirSync
control. A remote attacker with an RODC DC account could possibly use this
issue to obtain all domain secrets. (CVE-2023-4154)
Andrew Bartlett discovered that Samba incorrectly handled the rpcecho
development server. A remote attacker could possibly use this issue to
cause Samba to stop responding, resulting in a denial of service.
(CVE-2023-42669)
Kirin van der Veer discovered that Samba incorrectly handled certain RPC
service listeners. A remote attacke
Oracle
Oracle Oracle JD Edwards Risk Matrix: E1 Dev Platform Tech - Cloud (Samba) — CVE-2023-42670
vendor_oracle·2026-01-15·CVSS 6.5
CVE-2023-42670 [MEDIUM] Oracle Oracle JD Edwards Risk Matrix: E1 Dev Platform Tech - Cloud (Samba) — CVE-2023-42670
Oracle Oracle JD Edwards Risk Matrix: E1 Dev Platform Tech - Cloud (Samba) vulnerability
CVE: CVE-2023-42670
CVSS: 6.5
Protocol: SMB
Remote exploit: No
Affected versions: Network
Advisory: cpujan2026 (JAN 2026)
Ubuntu
Samba vulnerabilities
vendor_ubuntu·2023-10-17·CVSS 6.5
CVE-2023-42669 [MEDIUM] Samba vulnerabilities
Title: Samba vulnerabilities
Summary: Several security issues were fixed in Samba.
USN-6425-1 fixed vulnerabilities in Samba. This update provides the
corresponding updates for Ubuntu 23.10.
Original advisory details:
Sri Nagasubramanian discovered that the Samba acl_xattr VFS module
incorrectly handled read-only files. When Samba is configured to ignore
system ACLs, a remote attacker could possibly use this issue to truncate
read-only files. (CVE-2023-4091)
Andrew Bartlett discovered that Samba incorrectly handled the DirSync
control. A remote attacker with an RODC DC account could possibly use this
issue to obtain all domain secrets. (CVE-2023-4154)
Andrew Bartlett discovered that Samba incorrectly handled the rpcecho
development server. A remote attacker could possibly use this is
Ubuntu
Samba regression
vendor_ubuntu·2023-10-11·CVSS 6.5
[MEDIUM] Samba regression
Title: Samba regression
Summary: USN-6425-1 introduced a regression in Samba.
USN-6425-1 fixed vulnerabilities in Samba. Due to a build issue on Ubuntu
20.04 LTS, the update introduced regressions in macro handling and
possibly other functionality.
This update fixes the problem. We apologize for the inconvenience.
Original advisory details:
Sri Nagasubramanian discovered that the Samba acl_xattr VFS module
incorrectly handled read-only files. When Samba is configured to ignore
system ACLs, a remote attacker could possibly use this issue to truncate
read-only files. (CVE-2023-4091)
Andrew Bartlett discovered that Samba incorrectly handled the DirSync
control. A remote attacker with an RODC DC account could possibly use this
issue to obtain all domain secrets. (CVE-2023-4154)
Andrew B
Ubuntu
Samba vulnerabilities
vendor_ubuntu·2023-10-10·CVSS 6.5
CVE-2023-4091 [MEDIUM] Samba vulnerabilities
Title: Samba vulnerabilities
Summary: Several security issues were fixed in Samba.
Sri Nagasubramanian discovered that the Samba acl_xattr VFS module
incorrectly handled read-only files. When Samba is configured to ignore
system ACLs, a remote attacker could possibly use this issue to truncate
read-only files. (CVE-2023-4091)
Andrew Bartlett discovered that Samba incorrectly handled the DirSync
control. A remote attacker with an RODC DC account could possibly use this
issue to obtain all domain secrets. (CVE-2023-4154)
Andrew Bartlett discovered that Samba incorrectly handled the rpcecho
development server. A remote attacker could possibly use this issue to
cause Samba to stop responding, resulting in a denial of service.
(CVE-2023-42669)
Kirin van der Veer discovered that Samba incor
Red Hat
samba: AD DC Busy RPC multiple listener DoS
vendor_redhat·2023-10-10·CVSS 6.5
CVE-2023-42670 [MEDIUM] CWE-400 samba: AD DC Busy RPC multiple listener DoS
samba: AD DC Busy RPC multiple listener DoS
A flaw was found in Samba. It is susceptible to a vulnerability where multiple incompatible RPC listeners can be initiated, causing disruptions in the AD DC service. When Samba's RPC server experiences a high load or unresponsiveness, servers intended for non-AD DC purposes (for example, NT4-emulation "classic DCs") can erroneously start and compete for the same unix domain sockets. This issue leads to partial query responses from the AD DC, causing issues such as "The procedure number is out of range" when using tools like Active Directory Users. This flaw allows an attacker to disrupt AD DC services.
A flaw was found in Samba. It is susceptible to a vulnerability where multiple incompatible RPC listeners can be initiated, causing disruptions
Debian
CVE-2023-42670: samba - A flaw was found in Samba. It is susceptible to a vulnerability where multiple i...
vendor_debian·2023·CVSS 6.5
CVE-2023-42670 [MEDIUM] CVE-2023-42670: samba - A flaw was found in Samba. It is susceptible to a vulnerability where multiple i...
A flaw was found in Samba. It is susceptible to a vulnerability where multiple incompatible RPC listeners can be initiated, causing disruptions in the AD DC service. When Samba's RPC server experiences a high load or unresponsiveness, servers intended for non-AD DC purposes (for example, NT4-emulation "classic DCs") can erroneously start and compete for the same unix domain sockets. This issue leads to partial query responses from the AD DC, causing issues such as "The procedure number is out of range" when using tools like Active Directory Users. This flaw allows an attacker to disrupt AD DC services.
Scope: local
bookworm: resolved (fixed in 2:4.17.12+dfsg-0+deb12u1)
bullseye: resolved
forky: resolved (fixed in 2:4.19.1+dfsg-1)
sid: resolved (fixed in 2:4.19.1+dfsg-1)
trixie: resolved (f
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/security/cve/CVE-2023-42670https://bugzilla.redhat.com/show_bug.cgi?id=2241885https://bugzilla.samba.org/show_bug.cgi?id=15473https://www.samba.org/samba/security/CVE-2023-42670.htmlhttps://access.redhat.com/security/cve/CVE-2023-42670https://bugzilla.redhat.com/show_bug.cgi?id=2241885https://bugzilla.samba.org/show_bug.cgi?id=15473https://lists.fedoraproject.org/archives/list/[email protected]/message/ZUMVALLFFDFC53JZMUWA6HPD7HUGAP5I/https://security.netapp.com/advisory/ntap-20231124-0002/https://www.samba.org/samba/security/CVE-2023-42670.html
2023-11-03
Published