CVE-2021-43566
Summary
| CVE | CVE-2021-43566 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-01-11 16:15:00 UTC |
| Updated | 2022-10-14 11:42:00 UTC |
| Description | All versions of Samba prior to 4.13.16 are vulnerable to a malicious client using an SMB1 or NFS race to allow a directory to be created in an area of the server file system not exported under the share definition. Note that SMB1 has to be enabled, or the share also available via NFS in order for this attack to succeed. |
Risk And Classification
Problem Types: CWE-362
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 13979 – (CVE-2021-43566) CVE-2021-43566 [SECURITY] mkdir race condition allows share escape in Samba 4.x | MISC | bugzilla.samba.org | |
| CVE-2021-43566 Samba Vulnerability in NetApp Products | NetApp Product Security | CONFIRM | security.netapp.com | |
| Samba - Security Announcement Archive | MISC | www.samba.org | |
| Samba Release History | MISC | www.samba.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 180832 Debian Security Update for samba (CVE-2021-43566)
- 198651 Ubuntu Security Notification for Samba Vulnerabilities (USN-5260-1)
- 296057 Oracle Solaris 11.4 Support Repository Update (SRU) 44.113.4 Missing (bulletinapr2022)
- 355336 Amazon Linux Security Advisory for samba : ALAS2023-2023-032
- 501490 Alpine Linux Security Update for samba
- 671442 EulerOS Security Update for samba (EulerOS-SA-2022-1459)
- 671468 EulerOS Security Update for samba (EulerOS-SA-2022-1438)
- 671569 EulerOS Security Update for samba (EulerOS-SA-2022-1586)
- 671623 EulerOS Security Update for samba (EulerOS-SA-2022-1666)
- 671635 EulerOS Security Update for samba (EulerOS-SA-2022-1652)
- 690784 Free Berkeley Software Distribution (FreeBSD) Security Update for samba (8579074c-839f-11ec-a3b2-005056a311d1)
- 751680 OpenSUSE Security Update for samba (openSUSE-SU-2022:0283-1)
- 751683 SUSE Enterprise Linux Security Update for samba (SUSE-SU-2022:0323-1)
- 751994 SUSE Enterprise Linux Security Update for samba (SUSE-SU-2022:0283-1)
- 901488 Common Base Linux Mariner (CBL-Mariner) Security Update for samba (7489)