CVE Vulnerabilities

CVE-2017-9461

Loop with Unreachable Exit Condition ('Infinite Loop')

Published: Jun 06, 2017 | Modified: Apr 20, 2025
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
6.8 MEDIUM
AV:N/AC:L/Au:S/C:N/I:N/A:C
RedHat/V2
RedHat/V3
6.5 LOW
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

smbd in Samba before 4.4.10 and 4.5.x before 4.5.6 has a denial of service vulnerability (fd_open_atomic infinite loop with high CPU usage and memory consumption) due to wrongly handling dangling symlinks.

Weakness

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Affected Software

NameVendorStart VersionEnd Version
SambaSamba*4.4.9 (including)
SambaSamba4.5.0 (including)4.5.0 (including)
SambaSamba4.5.1 (including)4.5.1 (including)
SambaSamba4.5.2 (including)4.5.2 (including)
SambaSamba4.5.3 (including)4.5.3 (including)
SambaSamba4.5.4 (including)4.5.4 (including)
SambaSamba4.5.5 (including)4.5.5 (including)
Red Hat Enterprise Linux 7RedHatsamba-0:4.6.2-8.el7*
Red Hat Gluster Storage 3.2 for RHEL 7RedHatsamba-0:4.6.3-4.el7rhgs*
Red Hat Gluster Storage 3.3 for RHEL 6RedHatlibldb-0:1.1.29-1.el6rhs*
Red Hat Gluster Storage 3.3 for RHEL 6RedHatlibtalloc-0:2.1.9-1.el6rhs*
Red Hat Gluster Storage 3.3 for RHEL 6RedHatlibtdb-0:1.3.12-1.1.el6rhs*
Red Hat Gluster Storage 3.3 for RHEL 6RedHatlibtevent-0:0.9.31-1.el6rhs*
Red Hat Gluster Storage 3.3 for RHEL 6RedHatsamba-0:4.6.3-5.el6rhs*
SambaUbuntuesm-infra-legacy/trusty*
SambaUbuntuesm-infra/xenial*
SambaUbuntutrusty*
SambaUbuntutrusty/esm*
SambaUbuntuupstream*
SambaUbuntuxenial*
SambaUbuntuyakkety*

References