samba: symlink race permits opening files outside share directory
Published Mar 12, 2018
7.5
HIGHCVSS 3.1
EPSS 11.11%
Description
Samba before versions 4.6.1, 4.5.7 and 4.4.11 are vulnerable to a malicious client using a symlink race to allow access to areas of the server file system not exported under the share definition.
Affected products
-
- Version 4.4.11StatusaffectedConstraints-
- Version 4.5.7StatusaffectedConstraints-
- Version 4.6.1StatusaffectedConstraints-
- Version
Configuration 1
Configuration 2
- 8.0
- 6.0
- 7.0
No data.
Red Hat Enterprise Linux 6
samba-0:3.6.23-45.el6_9
Fixed · RHSA-2017:2789
Red Hat Enterprise Linux 7
samba-0:4.4.4-13.el7_3
Fixed · RHSA-2017:1265
Red Hat Gluster Storage 3.2 for RHEL 7
samba-0:4.6.3-4.el7rhgs
Fixed · RHSA-2017:2338
Red Hat Gluster Storage 3.3 for RHEL 6
libldb-0:1.1.29-1.el6rhs
Fixed · RHSA-2017:2778
Red Hat Gluster Storage 3.3 for RHEL 6
libtalloc-0:2.1.9-1.el6rhs
Fixed · RHSA-2017:2778
Red Hat Gluster Storage 3.3 for RHEL 6
libtdb-0:1.3.12-1.1.el6rhs
Fixed · RHSA-2017:2778
Red Hat Gluster Storage 3.3 for RHEL 6
libtevent-0:0.9.31-1.el6rhs
Fixed · RHSA-2017:2778
Red Hat Gluster Storage 3.3 for RHEL 6
samba-0:4.6.3-5.el6rhs
Fixed · RHSA-2017:2778
Red Hat Enterprise Linux 5
samba
Will not fix
Red Hat Enterprise Linux 5
samba3x
Will not fix
Red Hat Enterprise Linux 6
samba4
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | samba-0:3.6.23-45.el6_9 | Fixed | RHSA-2017:2789 |
| Red Hat Enterprise Linux 7 | samba-0:4.4.4-13.el7_3 | Fixed | RHSA-2017:1265 |
| Red Hat Gluster Storage 3.2 for RHEL 7 | samba-0:4.6.3-4.el7rhgs | Fixed | RHSA-2017:2338 |
| Red Hat Gluster Storage 3.3 for RHEL 6 | libldb-0:1.1.29-1.el6rhs | Fixed | RHSA-2017:2778 |
| Red Hat Gluster Storage 3.3 for RHEL 6 | libtalloc-0:2.1.9-1.el6rhs | Fixed | RHSA-2017:2778 |
| Red Hat Gluster Storage 3.3 for RHEL 6 | libtdb-0:1.3.12-1.1.el6rhs | Fixed | RHSA-2017:2778 |
| Red Hat Gluster Storage 3.3 for RHEL 6 | libtevent-0:0.9.31-1.el6rhs | Fixed | RHSA-2017:2778 |
| Red Hat Gluster Storage 3.3 for RHEL 6 | samba-0:4.6.3-5.el6rhs | Fixed | RHSA-2017:2778 |
| Red Hat Enterprise Linux 5 | samba | Will not fix | n/a |
| Red Hat Enterprise Linux 5 | samba3x | Will not fix | n/a |
| Red Hat Enterprise Linux 6 | samba4 | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Add the parameter: unix extensions = no to the [global] section of your smb.conf and restart smbd. This prevents SMB1 clients from creating symlinks on the exported file system using SMB1. However, if the same region of the file system is also exported using NFS, NFS clients can create symlinks that potentially can also hit the race condition. For non-patched versions of Samba we recommend only exporting areas of the file system by either SMB or NFS, not both.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:L/A:L
AV:N/AC:M/Au:S/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Table of values (24 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 11.11% (0.11109) | 95.81th | v5 (v2026.06.15) |
| Jun 15, 2026 | 11.18% (0.11181) | 95.38th | v5 (v2026.06.15) |
| May 24, 2026 | 47.49% (0.47493) | 97.74th | v4 (v2025.03.14) |
| May 23, 2026 | 53.69% (0.53691) | 98.03th | v4 (v2025.03.14) |
| Mar 10, 2026 | 41.14% (0.41136) | 97.32th | v4 (v2025.03.14) |
| Feb 18, 2026 | 39.06% (0.39062) | 97.17th | v4 (v2025.03.14) |
| Jan 8, 2026 | 22.63% (0.22627) | 95.66th | v4 (v2025.03.14) |
| Nov 30, 2025 | 18.12% (0.18121) | 94.91th | v4 (v2025.03.14) |
| Oct 19, 2025 | 22.80% (0.22797) | 95.61th | v4 (v2025.03.14) |
| Jul 24, 2025 | 19.05% (0.19053) | 95.04th | v4 (v2025.03.14) |
| Mar 30, 2025 | 20.26% (0.20260) | 95.04th | v4 (v2025.03.14) |
| Mar 29, 2025 | 30.64% (0.30635) | 94.82th | v4 (v2025.03.14) |
| Mar 20, 2025 | 20.26% (0.20260) | 95.07th | v4 (v2025.03.14) |
| Mar 17, 2025 | 21.55% (0.21547) | 95.25th | v4 (v2025.03.14) |
| Dec 17, 2024 | 8.02% (0.08021) | 94.28th | v3 (v2023.03.01) |
| Dec 12, 2024 | 1.66% (0.01658) | 88.11th | v3 (v2023.03.01) |
| May 19, 2024 | 1.51% (0.01514) | 86.97th | v3 (v2023.03.01) |
| Sep 12, 2023 | 1.66% (0.01658) | 86.05th | v3 (v2023.03.01) |
| Sep 3, 2023 | 1.96% (0.01959) | 87.25th | v3 (v2023.03.01) |
| Mar 7, 2023 | 2.13% (0.02126) | 87.44th | v3 (v2023.03.01) |
| Mar 6, 2023 | 16.20% (0.16204) | 96.11th | v2 (v2022.01.01) |
| Feb 4, 2022 | 16.20% (0.16204) | 92.74th | v2 (v2022.01.01) |
| Feb 3, 2022 | 10.22% (0.10225) | 87.52th | v5 (v2026.06.15) |
| Apr 14, 2021 | 10.22% (0.10225) | 0.00th | v1 |
References (14)
- http://www.securityfocus.com/bid/97033 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1038117 vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2017:1265 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2338 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2778 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2789 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2017-2619 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1429472 x_refsource_CONFIRMIssue TrackingThird Party Advisory
- https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbns03755en_us x_refsource_CONFIRMThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2017-2619
- https://www.cve.org/CVERecord?id=CVE-2017-2619
- https://www.debian.org/security/2017/dsa-3816 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- https://www.exploit-db.com/exploits/41740/ exploitx_refsource_EXPLOIT-DBThird Party AdvisoryVDB Entry
- https://www.samba.org/samba/security/CVE-2017-2619.html x_refsource_CONFIRMVendor Advisory
Change history (0)
No recorded changes yet.