Back

CRITICAL

samba: Use-after-free in processing SMB1 requests

Published Nov 27, 2017

Description

Use-after-free vulnerability in Samba 4.x before 4.7.3 allows remote attackers to execute arbitrary code via a crafted SMB1 request.

Affected products

Remediation

Red Hat mitigation

Prevent SMB1 access to the server by setting the parameter: "server min protocol = SMB2" to the [global] section of your smb.conf and restart smbd. This prevents and SMB1 access to the server. Note this could cause older clients to be unable to connect to the server.

Metrics

Weaknesses (1)

References (15)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Nov 27, 2017
Updated Aug 5, 2024
Reserved Sep 26, 2017
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Nov 21, 2017