Debian Samba vulnerabilities
192 known vulnerabilities affecting debian/samba.
Total CVEs
192
CISA KEV
2
actively exploited
Public exploits
20
Exploited in wild
5
Severity breakdown
CRITICAL16HIGH59MEDIUM90LOW27
Vulnerabilities
Page 8 of 10
CVE-2007-2444P4HIGHCVSS 7.2fixed in samba 3.0.25-1 (bookworm)2007
CVE-2007-2444 [HIGH] CVE-2007-2444: samba - Logic error in the SID/Name translation functionality in smbd in Samba 3.0.23d t...
Logic error in the SID/Name translation functionality in smbd in Samba 3.0.23d through 3.0.25pre2 allows local users to gain temporary privileges and execute SMB/CIFS protocol operations via unspecified vectors that cause the daemon to transition to the root user.
Scope: local
bookworm: resolved (fixed in 3.0.25-1)
bullseye: resolved (fixed in 3.0.25-1)
forky: resolved
debian
CVE-2019-14861P4MEDIUMCVSS 5.3fixed in samba 2:4.11.3+dfsg-1 (bookworm)2019
CVE-2019-14861 [MEDIUM] CVE-2019-14861: samba - All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before ...
All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the (poorly named) dnsserver RPC pipe provides administrative facilities to modify DNS records and zones. Samba, when acting as an AD DC, stores DNS records in LDAP. In AD, the default permissions on the DNS partition allow creation of new records by authentic
debian
CVE-2021-20251P4MEDIUMCVSS 5.9fixed in samba 2:4.17.2+dfsg-3 (bookworm)2021
CVE-2021-20251 [MEDIUM] CVE-2021-20251: samba - A flaw was found in samba. A race condition in the password lockout code may lea...
A flaw was found in samba. A race condition in the password lockout code may lead to the risk of brute force attacks being successful if special conditions are met.
Scope: local
bookworm: resolved (fixed in 2:4.17.2+dfsg-3)
bullseye: open
forky: resolved (fixed in 2:4.17.2+dfsg-3)
sid: resolved (fixed in 2:4.17.2+dfsg-3)
trixie: resolved (fixed in 2:4.17.2+dfsg-3)
debian
CVE-2022-32746P4MEDIUMCVSS 5.4fixed in samba 2:4.16.4+dfsg-1 (bookworm)2022
CVE-2022-32746 [MEDIUM] CVE-2022-32746: samba - A flaw was found in the Samba AD LDAP server. The AD DC database audit logging m...
A flaw was found in the Samba AD LDAP server. The AD DC database audit logging module can access LDAP message values freed by a preceding database module, resulting in a use-after-free issue. This issue is only possible when modifying certain privileged attributes, such as userAccountControl.
Scope: local
bookworm: resolved (fixed in 2:4.16.4+dfsg-1)
bullseye: resol
debian
CVE-2019-3870P4MEDIUMCVSS 6.1fixed in samba 2:4.9.5+dfsg-3 (bookworm)2019
CVE-2019-3870 [MEDIUM] CVE-2019-3870: samba - A vulnerability was found in Samba from version (including) 4.9 to versions befo...
A vulnerability was found in Samba from version (including) 4.9 to versions before 4.9.6 and 4.10.2. During the creation of a new Samba AD DC, files are created in a private subdirectory of the install location. This directory is typically mode 0700, that is owner (root) only access. However in some upgraded installations it will have other permissions, such as 0755,
debian
CVE-2018-1050P4MEDIUMCVSS 4.3fixed in samba 2:4.7.4+dfsg-2 (bookworm)2018
CVE-2018-1050 [MEDIUM] CVE-2018-1050: samba - All versions of Samba from 4.0.0 onwards are vulnerable to a denial of service a...
All versions of Samba from 4.0.0 onwards are vulnerable to a denial of service attack when the RPC spoolss service is configured to be run as an external daemon. Missing input sanitization checks on some of the input parameters to spoolss RPC calls could cause the print spooler service to crash.
Scope: local
bookworm: resolved (fixed in 2:4.7.4+dfsg-2)
bullseye: resol
debian
CVE-2020-10700P4MEDIUMCVSS 5.3fixed in samba 2:4.12.3+dfsg-2 (bookworm)2020
CVE-2020-10700 [MEDIUM] CVE-2020-10700: samba - A use-after-free flaw was found in the way samba AD DC LDAP servers, handled 'Pa...
A use-after-free flaw was found in the way samba AD DC LDAP servers, handled 'Paged Results' control is combined with the 'ASQ' control. A malicious user in a samba AD could use this flaw to cause denial of service. This issue affects all samba versions before 4.10.15, before 4.11.8 and before 4.12.2.
Scope: local
bookworm: resolved (fixed in 2:4.12.3+dfsg-2)
bullse
debian
CVE-2013-0214P4MEDIUMCVSS 5.1fixed in samba 2:3.6.6-5 (bookworm)2013
CVE-2013-0214 [MEDIUM] CVE-2013-0214: samba - Cross-site request forgery (CSRF) vulnerability in the Samba Web Administration ...
Cross-site request forgery (CSRF) vulnerability in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.21, 3.6.x before 3.6.12, and 4.x before 4.0.2 allows remote attackers to hijack the authentication of arbitrary users by leveraging knowledge of a password and composing requests that perform SWAT actions.
Scope: local
bookworm: resolved (fixed in 2:3.6.
debian
CVE-2014-0244P4LOWCVSS 3.3fixed in samba 2:4.1.9+dfsg-1 (bookworm)2014
CVE-2014-0244 [LOW] CVE-2014-0244: samba - The sys_recvfrom function in nmbd in Samba 3.6.x before 3.6.24, 4.0.x before 4.0...
The sys_recvfrom function in nmbd in Samba 3.6.x before 3.6.24, 4.0.x before 4.0.19, and 4.1.x before 4.1.9 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a malformed UDP packet.
Scope: local
bookworm: resolved (fixed in 2:4.1.9+dfsg-1)
bullseye: resolved (fixed in 2:4.1.9+dfsg-1)
forky: resolved (fixed in 2:4.1.9+dfsg-1)
sid
debian
CVE-2011-0719P4MEDIUMCVSS 5.0fixed in samba 2:3.5.7~dfsg-1 (bookworm)2011
CVE-2011-0719 [MEDIUM] CVE-2011-0719: samba - Samba 3.x before 3.3.15, 3.4.x before 3.4.12, and 3.5.x before 3.5.7 does not pe...
Samba 3.x before 3.3.15, 3.4.x before 3.4.12, and 3.5.x before 3.5.7 does not perform range checks for file descriptors before use of the FD_SET macro, which allows remote attackers to cause a denial of service (stack memory corruption, and infinite loop or daemon crash) by opening a large number of files, related to (1) Winbind or (2) smbd.
Scope: local
bookworm: res
debian
CVE-2019-14847P4MEDIUMCVSS 4.9fixed in samba 2:4.11.0+dfsg-6 (bookworm)2019
CVE-2019-14847 [MEDIUM] CVE-2019-14847: samba - A flaw was found in samba 4.0.0 before samba 4.9.15 and samba 4.10.x before 4.10...
A flaw was found in samba 4.0.0 before samba 4.9.15 and samba 4.10.x before 4.10.10. An attacker can crash AD DC LDAP server via dirsync resulting in denial of service. Privilege escalation is not possible with this issue.
Scope: local
bookworm: resolved (fixed in 2:4.11.0+dfsg-6)
bullseye: resolved (fixed in 2:4.11.0+dfsg-6)
forky: resolved (fixed in 2:4.11.0+dfsg-
debian
CVE-2025-0620P4LOWCVSS 4.9fixed in samba 2:4.22.2+dfsg-1 (forky)2025
CVE-2025-0620 [MEDIUM] CVE-2025-0620: samba - A flaw was found in Samba. The smbd service daemon does not pick up group member...
A flaw was found in Samba. The smbd service daemon does not pick up group membership changes when re-authenticating an expired SMB session. This issue can expose file shares until clients disconnect and then connect again.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 2:4.22.2+dfsg-1)
sid: resolved (fixed in 2:4.22.2+dfsg-1)
trixie: reso
debian
CVE-2012-6150P4LOWCVSS 3.6fixed in samba 2:4.0.13+dfsg-1 (bookworm)2012
CVE-2012-6150 [LOW] CVE-2012-6150: samba - The winbind_name_list_to_sid_string_list function in nsswitch/pam_winbind.c in S...
The winbind_name_list_to_sid_string_list function in nsswitch/pam_winbind.c in Samba through 4.1.2 handles invalid require_membership_of group names by accepting authentication by any user, which allows remote authenticated users to bypass intended access restrictions in opportunistic circumstances by leveraging an administrator's pam_winbind configuration-file mistake.
debian
CVE-2020-14318P4MEDIUMCVSS 4.3fixed in samba 2:4.13.2+dfsg-2 (bookworm)2020
CVE-2020-14318 [MEDIUM] CVE-2020-14318: samba - A flaw was found in the way samba handled file and directory permissions. An aut...
A flaw was found in the way samba handled file and directory permissions. An authenticated user could use this flaw to gain access to certain file and directory information which otherwise would be unavailable to the attacker.
Scope: local
bookworm: resolved (fixed in 2:4.13.2+dfsg-2)
bullseye: resolved (fixed in 2:4.13.2+dfsg-2)
forky: resolved (fixed in 2:4.13.2+d
debian
CVE-2006-3403P4MEDIUMCVSS 5.0fixed in samba 3.0.23a-1 (bookworm)2006
CVE-2006-3403 [MEDIUM] CVE-2006-3403: samba - The smdb daemon (smbd/service.c) in Samba 3.0.1 through 3.0.22 allows remote att...
The smdb daemon (smbd/service.c) in Samba 3.0.1 through 3.0.22 allows remote attackers to cause a denial of service (memory consumption) via a large number of share connection requests.
Scope: local
bookworm: resolved (fixed in 3.0.23a-1)
bullseye: resolved (fixed in 3.0.23a-1)
forky: resolved (fixed in 3.0.23a-1)
sid: resolved (fixed in 3.0.23a-1)
trixie: resolved (f
debian
CVE-2018-14628P4MEDIUMCVSS 4.3fixed in samba 2:4.17.12+dfsg-0+deb12u3 (bookworm)2018
CVE-2018-14628 [MEDIUM] CVE-2018-14628: samba - An information leak vulnerability was discovered in Samba's LDAP server. Due to ...
An information leak vulnerability was discovered in Samba's LDAP server. Due to missing access control checks, an authenticated but unprivileged attacker could discover the names and preserved attributes of deleted objects in the LDAP store.
Scope: local
bookworm: resolved (fixed in 2:4.17.12+dfsg-0+deb12u3)
bullseye: open
forky: resolved (fixed in 2:4.19.3+dfsg-1)
debian
CVE-2021-44141P4MEDIUMCVSS 4.3fixed in samba 2:4.16.0+dfsg-2 (bookworm)2021
CVE-2021-44141 [MEDIUM] CVE-2021-44141: samba - All versions of Samba prior to 4.15.5 are vulnerable to a malicious client using...
All versions of Samba prior to 4.15.5 are vulnerable to a malicious client using a server symlink to determine if a file or directory exists in an area of the server file system not exported under the share definition. SMB1 with unix extensions has to be enabled in order for this attack to succeed.
Scope: local
bookworm: resolved (fixed in 2:4.16.0+dfsg-2)
bullseye:
debian
CVE-2022-32742P4MEDIUMCVSS 4.3fixed in samba 2:4.16.4+dfsg-1 (bookworm)2022
CVE-2022-32742 [MEDIUM] CVE-2022-32742: samba - A flaw was found in Samba. Some SMB1 write requests were not correctly range-che...
A flaw was found in Samba. Some SMB1 write requests were not correctly range-checked to ensure the client had sent enough data to fulfill the write, allowing server memory contents to be written into the file (or printer) instead of client-supplied data. The client cannot control the area of the server memory written to the file (or printer).
Scope: local
bookworm:
debian
CVE-2010-1635P4LOWCVSS 5.0fixed in samba 2:3.6.1-2 (bookworm)2010
CVE-2010-1635 [MEDIUM] CVE-2010-1635: samba - The chain_reply function in process.c in smbd in Samba before 3.4.8 and 3.5.x be...
The chain_reply function in process.c in smbd in Samba before 3.4.8 and 3.5.x before 3.5.2 allows remote attackers to cause a denial of service (NULL pointer dereference and process crash) via a Negotiate Protocol request with a certain 0x0003 field value followed by a Session Setup AndX request with a certain 0x8003 field value.
Scope: local
bookworm: resolved (fixed
debian
CVE-2007-0452P4LOWCVSS 6.8fixed in samba 3.0.23d-5 (bookworm)2007
CVE-2007-0452 [MEDIUM] CVE-2007-0452: samba - smbd in Samba 3.0.6 through 3.0.23d allows remote authenticated users to cause a...
smbd in Samba 3.0.6 through 3.0.23d allows remote authenticated users to cause a denial of service (memory and CPU exhaustion) by renaming a file in a way that prevents a request from being removed from the deferred open queue, which triggers an infinite loop.
Scope: local
bookworm: resolved (fixed in 3.0.23d-5)
bullseye: resolved (fixed in 3.0.23d-5)
forky: resolved
debian