CVE Vulnerabilities

CVE-2009-2906

Loop with Unreachable Exit Condition ('Infinite Loop')

Published: Oct 07, 2009 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:N/I:N/A:P
RedHat/V2
2.3 MODERATE
AV:A/AC:M/Au:S/C:N/I:N/A:P
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

smbd in Samba 3.0 before 3.0.37, 3.2 before 3.2.15, 3.3 before 3.3.8, and 3.4 before 3.4.2 allows remote authenticated users to cause a denial of service (infinite loop) via an unanticipated oplock break notification reply packet.

Weakness

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Affected Software

NameVendorStart VersionEnd Version
SambaSamba*3.0.37 (excluding)
SambaSamba3.2.0 (including)3.2.15 (excluding)
SambaSamba3.3.0 (including)3.3.8 (excluding)
SambaSamba3.4.0 (including)3.4.0 (including)
SambaSamba3.4.1 (including)3.4.1 (including)
Red Hat Enterprise Linux 3RedHatsamba-0:3.0.9-1.3E.16*
Red Hat Enterprise Linux 4RedHatsamba-0:3.0.33-0.18.el4_8*
Red Hat Enterprise Linux 5RedHatsamba-0:3.0.33-3.15.el5_4*
Supplementary for Red Hat Enterprise Linux 5RedHatsamba3x-0:3.3.8-0.46.el5*
SambaUbuntudapper*
SambaUbuntudevel*
SambaUbuntuhardy*
SambaUbuntuintrepid*
SambaUbuntujaunty*

References