samba: talloc free on uninitialized stack pointer in netlogon server could lead to remote-code execution
Published Feb 24, 2015
10.0
HIGHCVSS 2.0
EPSS 88.01%
Description
The Netlogon server implementation in smbd in Samba 3.5.x and 3.6.x before 3.6.25, 4.0.x before 4.0.25, 4.1.x before 4.1.17, and 4.2.x before 4.2.0rc5 performs a free operation on an uninitialized stack pointer, which allows remote attackers to execute arbitrary code via crafted Netlogon packets that use the ServerPasswordSet RPC API, as demonstrated by packets reaching the _netr_ServerPasswordSet function in rpc_server/netlogon/srv_netlog_nt.c.
Affected products
No data.
Configuration 1
- 5
- 6.0
- 7.0
Configuration 2
- 3.5.0
- 3.5.1
- 3.5.2
- 3.5.3
- 3.5.4
- 3.5.5
- 3.5.6
- 3.5.7
- 3.5.8
- 3.5.9
- 3.5.10
- 3.5.11
- 3.5.12
- 3.5.13
- 3.5.14
- 3.5.15
- 3.5.16
- 3.5.17
- 3.5.18
- 3.5.19
- 3.5.20
- 3.5.21
- 3.5.22
- 3.6.0
- 3.6.1
- 3.6.2
- 3.6.10
- 3.6.11
- 3.6.12
- 3.6.13
- 3.6.14
- 3.6.15
- 3.6.16
- 3.6.17
- 3.6.18
- 3.6.19
- 3.6.20
- 3.6.21
- 3.6.22
- 3.6.23
- 3.6.24
- 4.0.0
- 4.0.1
- 4.0.2
- 4.0.3
- 4.0.4
- 4.0.5
- 4.0.6
- 4.0.7
- 4.0.8
- 4.0.9
- 4.0.10
- 4.0.11
- 4.0.12
- 4.0.13
- 4.0.14
- 4.0.15
- 4.0.16
- 4.0.17
- 4.0.18
- 4.0.19
- 4.0.20
- 4.0.21
- 4.0.22
- 4.0.23
- 4.0.24
- 4.1.0
- 4.1.1
- 4.1.2
- 4.1.3
- 4.1.4
- 4.1.5
- 4.1.6
- 4.1.7
- 4.1.8
- 4.1.9
- 4.1.10
- 4.1.11
- 4.1.12
- 4.1.13
- 4.1.14
- 4.1.15
- 4.1.16
- 4.2.0
- 4.2.0
- 4.2.0
- 4.2.0
Configuration 3
Configuration 4
- 12.04
- 14.04
- 14.10
No data.
Red Hat Enterprise Linux 5
samba3x-0:3.6.23-9.el5_11
Fixed · RHSA-2015:0249
Red Hat Enterprise Linux 5.6 Long Life
samba3x-0:3.5.4-0.70.el5_6.4
Fixed · RHSA-2015:0253
Red Hat Enterprise Linux 5.9 Extended Update Support
samba3x-0:3.6.6-0.131.el5_9
Fixed · RHSA-2015:0253
Red Hat Enterprise Linux 6
samba-0:3.6.23-14.el6_6
Fixed · RHSA-2015:0251
Red Hat Enterprise Linux 6
samba4-0:4.0.0-66.el6_6.rc4
Fixed · RHSA-2015:0250
Red Hat Enterprise Linux 6.2 Advanced Update Support
samba-0:3.5.10-119.el6_2
Fixed · RHSA-2015:0254
Red Hat Enterprise Linux 6.4 Extended Update Support
samba-0:3.6.9-151.el6_4.3
Fixed · RHSA-2015:0254
Red Hat Enterprise Linux 6.4 Extended Update Support
samba4-0:4.0.0-57.el6_4.rc4
Fixed · RHSA-2015:0255
Red Hat Enterprise Linux 6.5 Extended Update Support
samba-0:3.6.9-171.el6_5
Fixed · RHSA-2015:0254
Red Hat Enterprise Linux 6.5 Extended Update Support
samba4-0:4.0.0-65.el6_5.rc4
Fixed · RHSA-2015:0255
Red Hat Enterprise Linux 7
samba-0:4.1.1-38.el7_0
Fixed · RHSA-2015:0252
Red Hat Storage 2.1
samba-0:3.6.9-167.10.3.el6rhs
Fixed · RHSA-2015:0257
Red Hat Storage 3 for RHEL 6
samba-0:3.6.509-169.6.el6rhs
Fixed · RHSA-2015:0256
Red Hat Enterprise Linux 4
samba
Not affected
Red Hat Enterprise Linux 5
samba
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | samba3x-0:3.6.23-9.el5_11 | Fixed | RHSA-2015:0249 |
| Red Hat Enterprise Linux 5.6 Long Life | samba3x-0:3.5.4-0.70.el5_6.4 | Fixed | RHSA-2015:0253 |
| Red Hat Enterprise Linux 5.9 Extended Update Support | samba3x-0:3.6.6-0.131.el5_9 | Fixed | RHSA-2015:0253 |
| Red Hat Enterprise Linux 6 | samba-0:3.6.23-14.el6_6 | Fixed | RHSA-2015:0251 |
| Red Hat Enterprise Linux 6 | samba4-0:4.0.0-66.el6_6.rc4 | Fixed | RHSA-2015:0250 |
| Red Hat Enterprise Linux 6.2 Advanced Update Support | samba-0:3.5.10-119.el6_2 | Fixed | RHSA-2015:0254 |
| Red Hat Enterprise Linux 6.4 Extended Update Support | samba-0:3.6.9-151.el6_4.3 | Fixed | RHSA-2015:0254 |
| Red Hat Enterprise Linux 6.4 Extended Update Support | samba4-0:4.0.0-57.el6_4.rc4 | Fixed | RHSA-2015:0255 |
| Red Hat Enterprise Linux 6.5 Extended Update Support | samba-0:3.6.9-171.el6_5 | Fixed | RHSA-2015:0254 |
| Red Hat Enterprise Linux 6.5 Extended Update Support | samba4-0:4.0.0-65.el6_5.rc4 | Fixed | RHSA-2015:0255 |
| Red Hat Enterprise Linux 7 | samba-0:4.1.1-38.el7_0 | Fixed | RHSA-2015:0252 |
| Red Hat Storage 2.1 | samba-0:3.6.9-167.10.3.el6rhs | Fixed | RHSA-2015:0257 |
| Red Hat Storage 3 for RHEL 6 | samba-0:3.6.509-169.6.el6rhs | Fixed | RHSA-2015:0256 |
| Red Hat Enterprise Linux 4 | samba | Not affected | n/a |
| Red Hat Enterprise Linux 5 | samba | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue does not affect the version of samba package as shipped with Red Hat Enterprise Linux 4 and 5. It does affect the version of samba as shipped with Red Hat Enterprise Linux 6 and 7, as well as the version of samba3x shipped with Red Hat Enterprise Linux 5 and the version of samba4 as shipped with Red Hat Enterprise Linux 6. Red Hat Product Security has determined that this vulnerability has Important impact on Red Hat Enterprise Linux 7 because the Samba version shipped in this version of the operating system only executes the vulnerable code after a memory allocation failure, making it more difficult to exploit this flaw.
Red Hat mitigation
On Samba versions 4.0.0 and above, add the line: rpc_server:netlogon=disabled to the [global] section of your smb.conf. For Samba versions 3.6.x and earlier, this workaround is not available.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:C/I:C/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (17 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 88.01% (0.88008) | 99.76th | v5 (v2026.06.15) |
| Jun 15, 2026 | 88.60% (0.88597) | 99.75th | v5 (v2026.06.15) |
| Apr 24, 2026 | 91.08% (0.91081) | 99.65th | v4 (v2025.03.14) |
| Feb 1, 2026 | 89.54% (0.89539) | 99.55th | v4 (v2025.03.14) |
| Oct 5, 2025 | 90.93% (0.90928) | 99.62th | v4 (v2025.03.14) |
| Jul 3, 2025 | 92.17% (0.92168) | 99.70th | v4 (v2025.03.14) |
| Mar 21, 2025 | 91.03% (0.91034) | 99.64th | v4 (v2025.03.14) |
| Mar 17, 2025 | 88.94% (0.88937) | 99.50th | v4 (v2025.03.14) |
| Dec 12, 2024 | 97.42% (0.97421) | 99.96th | v3 (v2023.03.01) |
| May 10, 2024 | 97.43% (0.97426) | 99.94th | v3 (v2023.03.01) |
| Jan 31, 2024 | 97.40% (0.97400) | 99.91th | v3 (v2023.03.01) |
| Apr 23, 2023 | 97.42% (0.97421) | 99.87th | v3 (v2023.03.01) |
| Mar 7, 2023 | 97.41% (0.97407) | 99.84th | v3 (v2023.03.01) |
| Mar 6, 2023 | 95.14% (0.95138) | 99.96th | v2 (v2022.01.01) |
| Feb 13, 2023 | 95.14% (0.95138) | 99.96th | v2 (v2022.01.01) |
| Feb 3, 2023 | 87.01% (0.87006) | 99.72th | v2 (v2022.01.01) |
| Feb 4, 2022 | 95.14% (0.95138) | 99.97th | v2 (v2022.01.01) |
References (39)
- http://advisories.mageia.org/MGASA-2015-0084.html x_refsource_CONFIRM
- http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00028.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00030.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00031.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00035.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00042.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00047.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00048.html vendor-advisoryx_refsource_SUSE
- http://marc.info/?l=bugtraq&m=142722696102151&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=143039217203031&w=2 vendor-advisoryx_refsource_HP
- http://rhn.redhat.com/errata/RHSA-2015-0249.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2015-0250.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2015-0251.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2015-0252.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2015-0253.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2015-0254.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2015-0255.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2015-0256.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2015-0257.html vendor-advisoryx_refsource_REDHAT
- http://security.gentoo.org/glsa/glsa-201502-15.xml vendor-advisoryx_refsource_GENTOO
- http://www.debian.org/security/2015/dsa-3171 vendor-advisoryx_refsource_DEBIAN
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:081 vendor-advisoryx_refsource_MANDRIVA
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:082 vendor-advisoryx_refsource_MANDRIVA
- http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.html x_refsource_CONFIRM
- http://www.securityfocus.com/bid/72711 vdb-entryx_refsource_BID
- http://www.securitytracker.com/id/1031783 vdb-entryx_refsource_SECTRACK
- http://www.slackware.com/security/viewer.php?l=slackware-security&y=2015&m=slackware-security.360345 vendor-advisoryx_refsource_SLACKWARE
- http://www.ubuntu.com/usn/USN-2508-1 vendor-advisoryx_refsource_UBUNTU
- https://access.redhat.com/articles/1346913 x_refsource_CONFIRM
- https://access.redhat.com/security/cve/CVE-2015-0240 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1191325 x_refsource_CONFIRMIssue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2015-0240
- https://security.netapp.com/advisory/ntap-20250509-0001/
- https://securityblog.redhat.com/2015/02/23/samba-vulnerability-cve-2015-0240/ x_refsource_CONFIRMExploit
- https://support.lenovo.com/product_security/samba_remote_vuln x_refsource_CONFIRM
- https://support.lenovo.com/us/en/product_security/samba_remote_vuln x_refsource_CONFIRM
- https://www.cve.org/CVERecord?id=CVE-2015-0240
- https://www.exploit-db.com/exploits/36741/ exploitx_refsource_EXPLOIT-DB
- https://www.samba.org/samba/security/CVE-2015-0240 x_refsource_CONFIRMVendor Advisory
Change history (0)
No recorded changes yet.