CVE-2018-16841 PUBLISHED

Samba from version 4.3.0 and before versions 4.7.12, 4.8.7 and 4.9.3 are vulnerable to a denial of service. When configured to accept smart-card authentication, Samba's KDC will call talloc_free() twice on the same memory if the principal in a validly signed certificate does not match the principal in the AS-REQ. This is only possible after authentication with a trusted certificate. talloc is robust against further corruption from a double-free with talloc_free() and directly calls abort(), terminating the KDC process.

EPSS 7.11% · 91.5th percentile

Risk Scores

EPSS Score
7.11%
91.5th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSsamba2:4.1.6+dfsg-1ubuntu2.14.04.11, 2:3.6.18-1ubuntu3, 2:4.0.10+dfsg-4ubuntu2
Ubuntu:18.04:LTSsamba0, 2:4.6.7+dfsg-1ubuntu3, 2:4.7.1+dfsg-1ubuntu1
Ubuntu:16.04:LTSsamba2:4.3.6+dfsg-1ubuntu1, 2:4.3.8+dfsg-0ubuntu1, 2:4.3.9+dfsg-0ubuntu0.16.04.1

Timeline

References

Open in Interactive Console →