QID 38857

Date Published: 2022-02-01

QID 38857: Samba Out-Of-Bounds Heap Read/Write Vulnerability

All versions of Samba prior to 4.13.17 are vulnerable to an out-of-bounds heap read write vulnerability that allows remote attackers to execute arbitrary code as root on affected Samba installations that use the VFS module vfs_fruit.
The problem in vfs_fruit exists in the default configuration of the fruit VFS module using fruit:metadata=netatalk or fruit:resource=file. If both options are set to different settings than the default values, the system is not affected by the security issue.

Affected Versions:
All versions of Samba prior to 4.13.17 are vulnerable

QID Detection Logic (Unauthenticated)
This QID checks for vulnerable version of Samba from the banner of SAMBA service.

Successful exploitation of the vulnerability may allow a remote attacker to execute arbitrary code as root user on affected Samba installations.

  • CVSS V3 rated as Critical - 9.9 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution

    Customers are advised to update to Samba Version 4.13.17, 4.14.12, 4.15.5 or later to patch the vulnerability. For more information please refer to the following Samba Security Advisory

    Workaround:
    As a workaround remove the "fruit" VFS module from the list of configured VFS objects in any "vfs objects" line in the Samba configuration smb.conf.
    Note that changing the VFS module settings fruit:metadata or fruit:resource to use the unaffected setting causes all stored information to be inaccessible and will make it appear to macOS clients as if the information is lost.

    Vendor References

    CVEs related to QID 38857

    Software Advisories
    Advisory ID Software Component Link
    NA URL Logo www.samba.org/samba/security/CVE-2021-44142.html