CVE-2021-3670

Summary

CVECVE-2021-3670
StatePUBLIC
Assigner[email protected]
Source PriorityCVE Program / NVD first with legacy fallback
Published2022-08-23 16:15:00 UTC
Updated2023-09-17 09:15:00 UTC
DescriptionMaxQueryDuration not honoured in Samba AD DC LDAP

Risk And Classification

Problem Types: NVD-CWE-noinfo

NVD Known Affected Configurations (CPE 2.3)

TypeVendorProductVersionUpdateEditionLanguage
Operating System Fedoraproject Fedora 35 All All All
Application Redhat Storage 3.0 All All All
Application Samba Samba All All All All

References

ReferenceSourceLinkTags
CVE-2021-3670 dsdb/anr: Do a copy of the potentially anr query before starting to modify it (5f059036) · Commits · The Samba Team / Samba · GitLab MISC gitlab.com
CVE-2021-3670 ldap_server: Set timeout on requests based on MaxQueryDuration (86fe9d48) · Commits · The Samba Team / Samba · GitLab MISC gitlab.com
CVE-2021-3670 ldap_server: Clearly log LDAP queries and timeouts (3507e96b) · Commits · The Samba Team / Samba · GitLab MISC gitlab.com
CVE-2021-3670 ldb: Confirm the request has not yet timed out in ldb filter processing (1d5b1556) · Commits · The Samba Team / Samba · GitLab MISC gitlab.com
CVE-2021-3670 ldap_server: Remove duplicate print of LDAP search details (2b3af3b5) · Commits · The Samba Team / Samba · GitLab MISC gitlab.com
CVE-2021-3670 tests/krb5/test_ldap.py: Add test for LDAP timeouts (dcfcafdb) · Commits · The Samba Team / Samba · GitLab MISC gitlab.com
Samba: Multiple Vulnerabilities (GLSA 202309-06) — Gentoo security MISC security.gentoo.org
CVE-2021-3670 ldap_server: Ensure value of MaxQueryDuration is greater than zero (e1ab0c43) · Commits · The Samba Team / Samba · GitLab MISC gitlab.com
14694 – (CVE-2021-3670) CVE-2021-3670 [SECURITY] MaxQueryDuration not honoured in Samba AD DC LDAP MISC bugzilla.samba.org
2077533 – (CVE-2021-3670) CVE-2021-3670 samba: MaxQueryDuration not honoured in Samba AD DC LDAP MISC bugzilla.redhat.com
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

Legacy QID Mappings

  • 180150 Debian Security Update for ldb (CVE-2021-3670)
  • 198878 Ubuntu Security Notification for Samba Vulnerabilities (USN-5542-1)
  • 502789 Alpine Linux Security Update for samba
  • 505682 Alpine Linux Security Update for samba
  • 671918 EulerOS Security Update for samba (EulerOS-SA-2022-2011)
  • 671954 EulerOS Security Update for samba (EulerOS-SA-2022-1981)
  • 672025 EulerOS Security Update for samba (EulerOS-SA-2022-2262)
  • 672058 EulerOS Security Update for samba (EulerOS-SA-2022-2249)
  • 672587 EulerOS Security Update for samba (EulerOS-SA-2023-1336)
  • 710751 Gentoo Linux Samba Multiple Vulnerabilities (GLSA 202309-06)
  • 752114 SUSE Enterprise Linux Security Update for ldb (SUSE-SU-2022:1576-1)
  • 752303 SUSE Enterprise Linux Security Update for ldb, samba (SUSE-SU-2022:2307-1)
  • 903822 Common Base Linux Mariner (CBL-Mariner) Security Update for samba (10662)
© CVE.report 2026 |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

CVE.report and Source URL Uptime Status status.cve.report