A flaw was found in samba. The Samba smbd file server must map Windows group identities (SIDs) into unix group ids (gids). The code that performs this had a flaw that could allow it to read data beyond the end of the array in the case where a negative cache entry had been added to the mapping cache. This could cause the calling code to return those values into the process token that stores the group membership for a user. The highest threat from this vulnerability is to data confidentiality and integrity.
The product reads data past the end, or before the beginning, of the intended buffer.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Samba | Samba | 3.6.0 (including) | 4.12.15 (excluding) |
Samba | Samba | 4.13.0 (including) | 4.13.8 (excluding) |
Samba | Samba | 4.14.0 (including) | 4.14.4 (excluding) |
Red Hat Enterprise Linux 7 | RedHat | samba-0:4.10.16-15.el7_9 | * |
Red Hat Enterprise Linux 7.7 Advanced Update Support | RedHat | samba-0:4.9.1-11.el7_7 | * |
Red Hat Enterprise Linux 7.7 Telco Extended Update Support | RedHat | samba-0:4.9.1-11.el7_7 | * |
Red Hat Enterprise Linux 7.7 Update Services for SAP Solutions | RedHat | samba-0:4.9.1-11.el7_7 | * |
Red Hat Enterprise Linux 8 | RedHat | samba-0:4.13.3-5.el8_4 | * |
Red Hat Enterprise Linux 8.2 Extended Update Support | RedHat | samba-0:4.11.2-15.el8_2 | * |
Red Hat Gluster Storage 3.5 for RHEL 7 | RedHat | samba-0:4.11.6-112.el7rhgs | * |
Red Hat Gluster Storage 3.5 for RHEL 8 | RedHat | samba-0:4.14.5-201.el8rhgs | * |
Samba | Ubuntu | bionic | * |
Samba | Ubuntu | devel | * |
Samba | Ubuntu | focal | * |
Samba | Ubuntu | groovy | * |
Samba | Ubuntu | hirsute | * |
Samba | Ubuntu | precise/esm | * |
Samba | Ubuntu | trusty | * |
Samba | Ubuntu | trusty/esm | * |
Samba | Ubuntu | upstream | * |
Samba | Ubuntu | xenial | * |