samba: save registry file outside share as unprivileged user
Published Apr 9, 2019
5.4
MEDIUMCVSS 3.1
EPSS 3.24%
Description
A flaw was found in the way samba implemented an RPC endpoint emulating the Windows registry service API. An unprivileged attacker could use this flaw to create a new registry hive file anywhere they have unix permissions which could lead to creation of a new file in the Samba share. Versions before 4.8.11, 4.9.6 and 4.10.2 are vulnerable.
Affected products
-
- Version 4.10.2StatusaffectedConstraints-
- Version 4.8.11StatusaffectedConstraints-
- Version 4.9.6StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| The Samba Project | Samba | n/a |
|
Configuration 1
Configuration 2
- 8.0
Configuration 3
- 3.0
- 7.0
Configuration 4
- 28
- 29
- 30
No data.
Red Hat Enterprise Linux 7
samba-0:4.9.1-6.el7
Fixed · RHSA-2019:2099
Red Hat Enterprise Linux 8
samba-0:4.10.4-1.el8
Fixed · RHSA-2019:3582
Red Hat Enterprise Linux 8
samba-0:4.10.4-1.el8
Fixed · RHSA-2019:3582
Red Hat Gluster Storage 3.4 for RHEL 6
libtalloc-0:2.1.14-3.el6rhs
Fixed · RHSA-2019:1967
Red Hat Gluster Storage 3.4 for RHEL 6
libtdb-0:1.3.16-3.el6rhs
Fixed · RHSA-2019:1967
Red Hat Gluster Storage 3.4 for RHEL 6
libtevent-0:0.9.37-3.el6rhs
Fixed · RHSA-2019:1967
Red Hat Gluster Storage 3.4 for RHEL 6
samba-0:4.9.8-105.el6rhs
Fixed · RHSA-2019:1967
Red Hat Gluster Storage 3.4 for RHEL 7
libtalloc-0:2.1.14-3.el7rhgs
Fixed · RHSA-2019:1966
Red Hat Gluster Storage 3.4 for RHEL 7
libtdb-0:1.3.16-3.el7rhgs
Fixed · RHSA-2019:1966
Red Hat Gluster Storage 3.4 for RHEL 7
libtevent-0:0.9.37-3.el7rhgs
Fixed · RHSA-2019:1966
Red Hat Gluster Storage 3.4 for RHEL 7
samba-0:4.9.8-105.el7rhgs
Fixed · RHSA-2019:1966
Red Hat Enterprise Linux 5
samba
Will not fix
Red Hat Enterprise Linux 6
samba
Will not fix
Red Hat Enterprise Linux 6
samba4
Will not fix
Red Hat Virtualization 4
redhat-virtualization-host
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | samba-0:4.9.1-6.el7 | Fixed | RHSA-2019:2099 |
| Red Hat Enterprise Linux 8 | samba-0:4.10.4-1.el8 | Fixed | RHSA-2019:3582 |
| Red Hat Enterprise Linux 8 | samba-0:4.10.4-1.el8 | Fixed | RHSA-2019:3582 |
| Red Hat Gluster Storage 3.4 for RHEL 6 | libtalloc-0:2.1.14-3.el6rhs | Fixed | RHSA-2019:1967 |
| Red Hat Gluster Storage 3.4 for RHEL 6 | libtdb-0:1.3.16-3.el6rhs | Fixed | RHSA-2019:1967 |
| Red Hat Gluster Storage 3.4 for RHEL 6 | libtevent-0:0.9.37-3.el6rhs | Fixed | RHSA-2019:1967 |
| Red Hat Gluster Storage 3.4 for RHEL 6 | samba-0:4.9.8-105.el6rhs | Fixed | RHSA-2019:1967 |
| Red Hat Gluster Storage 3.4 for RHEL 7 | libtalloc-0:2.1.14-3.el7rhgs | Fixed | RHSA-2019:1966 |
| Red Hat Gluster Storage 3.4 for RHEL 7 | libtdb-0:1.3.16-3.el7rhgs | Fixed | RHSA-2019:1966 |
| Red Hat Gluster Storage 3.4 for RHEL 7 | libtevent-0:0.9.37-3.el7rhgs | Fixed | RHSA-2019:1966 |
| Red Hat Gluster Storage 3.4 for RHEL 7 | samba-0:4.9.8-105.el7rhgs | Fixed | RHSA-2019:1966 |
| Red Hat Enterprise Linux 5 | samba | Will not fix | n/a |
| Red Hat Enterprise Linux 6 | samba | Will not fix | n/a |
| Red Hat Enterprise Linux 6 | samba4 | Will not fix | n/a |
| Red Hat Virtualization 4 | redhat-virtualization-host | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue affects the version of samba shipped with Red Hat Gluster Storage 3, as it contains the vulnerable functionality.
Red Hat mitigation
Either turn off SMB1 by setting the global parameter: 'min protocol = SMB2' or if SMB1 is required turn off unix extensions by setting the global parameter: 'unix extensions = no' in the smb.conf file.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L
AV:N/AC:L/Au:S/C:N/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 2, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Table of values (20 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 2, 2026 | 3.24% (0.03240) | 87.86th | v5 (v2026.06.15) |
| Jun 15, 2026 | 3.39% (0.03392) | 87.22th | v5 (v2026.06.15) |
| Nov 21, 2025 | 3.10% (0.03096) | 86.30th | v4 (v2025.03.14) |
| Nov 18, 2025 | 1.69% (0.01688) | 80.71th | v4 (v2025.03.14) |
| Mar 30, 2025 | 3.10% (0.03098) | 85.61th | v4 (v2025.03.14) |
| Mar 29, 2025 | 5.16% (0.05162) | 82.76th | v4 (v2025.03.14) |
| Mar 17, 2025 | 3.35% (0.03354) | 86.50th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.13% (0.00126) | 48.89th | v3 (v2023.03.01) |
| Apr 2, 2024 | 0.23% (0.00228) | 60.42th | v3 (v2023.03.01) |
| Nov 8, 2023 | 0.14% (0.00142) | 49.72th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.13% (0.00130) | 46.11th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.55% (0.01547) | 74.98th | v2 (v2022.01.01) |
| Feb 23, 2023 | 1.55% (0.01547) | 74.94th | v2 (v2022.01.01) |
| Dec 30, 2022 | 18.26% (0.18256) | 96.15th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.55% (0.01547) | 72.92th | v2 (v2022.01.01) |
| Feb 4, 2022 | 18.26% (0.18256) | 93.55th | v2 (v2022.01.01) |
| Feb 3, 2022 | 13.21% (0.13208) | 89.07th | v1 |
| Jan 6, 2022 | 13.21% (0.13208) | 88.94th | v1 |
| Jan 5, 2022 | 3.28% (0.03281) | 82.11th | v5 (v2026.06.15) |
| Apr 14, 2021 | 3.28% (0.03281) | 0.00th | v1 |
References (20)
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00050.html vendor-advisoryx_refsource_SUSEMailing ListPatchThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00106.html vendor-advisoryx_refsource_SUSEThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:1966 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:1967 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2099 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3582 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2019-3880 Vendor Advisory
- https://access.redhat.com/security/cve/cve-2019-3880 MitigationThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1691518 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3880 x_refsource_CONFIRMIssue TrackingMitigationThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/04/msg00013.html mailing-listx_refsource_MLISTThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6354GALK73CZWQKFUG7AWB6EIEGFMF62/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HSRLRO7BPRFETVFZ4TVJL2VFZEPHKJY4/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JTJVFA3RZ6G2IZDTVKLHRMX6QBYA4GPA/ vendor-advisoryx_refsource_FEDORA
- https://nvd.nist.gov/vuln/detail/CVE-2019-3880
- https://security.netapp.com/advisory/ntap-20190411-0004/ x_refsource_CONFIRMThird Party Advisory
- https://support.f5.com/csp/article/K20804356 x_refsource_CONFIRMThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-3880
- https://www.samba.org/samba/security/CVE-2019-3880.html x_refsource_MISCMitigationPatchVendor Advisory
- https://www.synology.com/security/advisory/Synology_SA_19_15 x_refsource_CONFIRMThird Party Advisory
Change history (0)
No recorded changes yet.