CVE-2022-2127
Description
RHSA-2023:7139: samba security, bug fix, and enhancement update (Moderate)
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Mitigation details
Description samba: out-of-bounds read in winbind AUTH_CRAP CVSS v3: 5.9 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H) Errata / fixed releases ProductPackageAdvisoryReleased Red Hat Enterprise Linux 8samba-0:4.18.6-1.el8RHSA-2023:71392023-11-14T00:00:00Z Red Hat Enterprise Linux 8samba-0:4.18.6-1.el8RHSA-2023:71392023-11-14T00:00:00Z Red Hat Enterprise Linux 8.6 Extended Updateβ¦
Description
samba: out-of-bounds read in winbind AUTH_CRAP
CVSS v3: 5.9 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H)
Errata / fixed releases
| Product | Package | Advisory | Released |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | samba-0:4.18.6-1.el8 | RHSA-2023:7139 | 2023-11-14T00:00:00Z |
| Red Hat Enterprise Linux 8 | samba-0:4.18.6-1.el8 | RHSA-2023:7139 | 2023-11-14T00:00:00Z |
| Red Hat Enterprise Linux 8.6 Extended Update Support | samba-0:4.15.5-15.el8_6 | RHSA-2024:0423 | 2024-01-25T00:00:00Z |
| Red Hat Enterprise Linux 8.8 Extended Update Support | samba-0:4.17.5-5.el8_8 | RHSA-2024:0580 | 2024-01-30T00:00:00Z |
| Red Hat Enterprise Linux 9 | samba-0:4.18.6-100.el9 | RHSA-2023:6667 | 2023-11-07T00:00:00Z |
| Red Hat Enterprise Linux 9 | samba-0:4.18.6-100.el9 | RHSA-2023:6667 | 2023-11-07T00:00:00Z |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 8 | samba-0:4.15.5-15.el8_6 | RHSA-2024:0423 | 2024-01-25T00:00:00Z |
Package state
| Product | Package | State |
|---|---|---|
| Red Hat Enterprise Linux 6 | samba | Out of support scope |
| Red Hat Enterprise Linux 6 | samba4 | Out of support scope |
| Red Hat Enterprise Linux 7 | samba | Out of support scope |
| Red Hat Storage 3 | samba | Out of support scope |
Apply commands
yum update -y samba
# or:
dnf upgrade -y samba
OS impact
SUSE Affected 1 release
| Version | Status | Fixed in |
|---|---|---|
| β | Affected | β |
AlmaLinux Fixed 2 releases
| Version | Status | Fixed in |
|---|---|---|
| 9 | Fixed | samba-krb5-printing-4.18.6-100.el9.aarch64.rpm |
| 8 | Fixed | samba-common-libs-4.18.6-1.el8.i686.rpm |
Debian Fixed 5 releases
| Version | Status | Fixed in |
|---|---|---|
| trixie | Fixed | 2:4.18.5+dfsg-1 |
| sid | Fixed | 2:4.18.5+dfsg-1 |
| forky | Fixed | 2:4.18.5+dfsg-1 |
| bullseye | Fixed | 2:4.13.13+dfsg-1~deb11u6 |
| bookworm | Fixed | 2:4.17.10+dfsg-0+deb12u1 |
Red Hat Fixed 2 releases
| Version | Status | Fixed in |
|---|---|---|
| 9 | Fixed | β |
| 8 | Fixed | β |
References
- https://access.redhat.com/errata/RHSA-2023:6667
- https://www.suse.com/security/cve/CVE-2022-2127.html
- https://security-tracker.debian.org/tracker/CVE-2022-2127
- https://access.redhat.com/errata/RHSA-2023:7139
- https://bugzilla.redhat.com/2222791
- https://bugzilla.redhat.com/2222793
- https://bugzilla.redhat.com/2222794
- https://bugzilla.redhat.com/2222795
- https://errata.almalinux.org/8/ALSA-2023-7139.html
- https://errata.almalinux.org/9/ALSA-2023-6667.html
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.