Samba: out-of-bounds read in winbind auth_crap
Published Jul 20, 2023
5.9
MEDIUMCVSS 3.1
EPSS 1.72%
Description
An out-of-bounds read vulnerability was found in Samba due to insufficient length checks in winbindd_pam_auth_crap.c. When performing NTLM authentication, the client replies to cryptographic challenges back to the server. These replies have variable lengths, and Winbind fails to check the lan manager response length. When Winbind is used for NTLM authentication, a maliciously crafted request can trigger an out-of-bounds read in Winbind, possibly resulting in a crash.
Affected products
No data.
Configuration 1
Configuration 2
- 6.0
- 7.0
- 8.0
- 9.0
Configuration 3
- 37
- 38
Configuration 4
- 12.0
No data.
Red Hat Enterprise Linux 8
samba-0:4.18.6-1.el8
Fixed · RHSA-2023:7139
Red Hat Enterprise Linux 8
samba-0:4.18.6-1.el8
Fixed · RHSA-2023:7139
Red Hat Enterprise Linux 8.6 Extended Update Support
samba-0:4.15.5-15.el8_6
Fixed · RHSA-2024:0423
Red Hat Enterprise Linux 8.8 Extended Update Support
samba-0:4.17.5-5.el8_8
Fixed · RHSA-2024:0580
Red Hat Enterprise Linux 9
samba-0:4.18.6-100.el9
Fixed · RHSA-2023:6667
Red Hat Enterprise Linux 9
samba-0:4.18.6-100.el9
Fixed · RHSA-2023:6667
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8
samba-0:4.15.5-15.el8_6
Fixed · RHSA-2024:0423
Red Hat Enterprise Linux 6
samba
Out of support scope
Red Hat Enterprise Linux 6
samba4
Out of support scope
Red Hat Enterprise Linux 7
samba
Out of support scope
Red Hat Storage 3
samba
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | samba-0:4.18.6-1.el8 | Fixed | RHSA-2023:7139 |
| Red Hat Enterprise Linux 8 | samba-0:4.18.6-1.el8 | Fixed | RHSA-2023:7139 |
| Red Hat Enterprise Linux 8.6 Extended Update Support | samba-0:4.15.5-15.el8_6 | Fixed | RHSA-2024:0423 |
| Red Hat Enterprise Linux 8.8 Extended Update Support | samba-0:4.17.5-5.el8_8 | Fixed | RHSA-2024:0580 |
| Red Hat Enterprise Linux 9 | samba-0:4.18.6-100.el9 | Fixed | RHSA-2023:6667 |
| Red Hat Enterprise Linux 9 | samba-0:4.18.6-100.el9 | Fixed | RHSA-2023:6667 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 8 | samba-0:4.15.5-15.el8_6 | Fixed | RHSA-2024:0423 |
| Red Hat Enterprise Linux 6 | samba | Out of support scope | n/a |
| Red Hat Enterprise Linux 6 | samba4 | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | samba | Out of support scope | n/a |
| Red Hat Storage 3 | samba | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (14)
- https://access.redhat.com/errata/RHSA-2023:6667 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2023:7139 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2024:0423 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2024:0580 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2022-2127 vdb-entryx_refsource_REDHATThird Party AdvisoryVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2222791 issue-trackingx_refsource_REDHATIssue TrackingThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2024/04/msg00015.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BPCSGND7LO467AJGR5DYBGZLTCGTOBCC/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OT74M42E6C36W7PQVY3OS4ZM7DVYB64Z/
- https://nvd.nist.gov/vuln/detail/CVE-2022-2127
- https://security.netapp.com/advisory/ntap-20230731-0010/
- https://www.cve.org/CVERecord?id=CVE-2022-2127
- https://www.debian.org/security/2023/dsa-5477
- https://www.samba.org/samba/security/CVE-2022-2127.html MitigationVendor Advisory
Change history (0)
No recorded changes yet.