A flaw was found in samba versions 4.0.0 to 4.5.2. The Samba routine ndr_pull_dnsp_name contains an integer wrap problem, leading to an attacker-controlled memory overwrite. ndr_pull_dnsp_name parses data from the Samba Active Directory ldb database. Any user who can write to the dnsRecord attribute over LDAP can trigger this memory corruption. By default, all authenticated LDAP users can write to the dnsRecord attribute on new DNS objects. This makes the defect a remote privilege escalation.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
- CVSS 3.0 Base Score: 8.1
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade samba | Nov 1, 2018 | Nov 1, 2018 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Nov 1, 2018 |
| Debian | — | Upgrade samba | Dec 20, 2016 | Dec 19, 2016 |
| Freebsd | — | Upgrade samba42Upgrade samba4Upgrade samba45Upgrade samba36Upgrade samba41Upgrade samba44Upgrade samba43 | Dec 28, 2016 | Dec 26, 2016 |
| Oracle Solaris | — | Upgrade service/network/samba to version 4.4.8-0.175.3.17.0.3.0 on Solaris 11.3Upgrade library/samba/libsmbclient to version 4.4.8-0.175.3.17.0.3.0 on Solaris 11.3 | May 29, 2017 | May 29, 2017 |
| Samba | — | Upgrade to Samba version 4.4.8Upgrade to Samba version 4.3.13Upgrade to Samba version 4.5.3 | Dec 20, 2016 | Dec 20, 2016 |
| Suse | — | Upgrade libgensec0-32bitUpgrade libdcerpc-samr0Upgrade libndr-krb5pac0Upgrade libdcerpc-atsvc-develUpgrade ctdb-develUpgrade ctdb-debuginfoUpgrade libdcerpc-atsvc0Upgrade libndr0-debuginfo-32bitUpgrade libsamba-hostconfig0-32bitUpgrade libgensec0Upgrade samba-libs-python3-32bitUpgrade libsamba-passdb0-32bitUpgrade libndr0Upgrade libdcerpc-samr0-debuginfo-32bitUpgrade libdcerpc-binding0-debuginfoUpgrade samba-core-develUpgrade libsamba-hostconfig0-debuginfoUpgrade libsmbconf0-debuginfoUpgrade libsamba-hostconfig-develUpgrade ctdb-tests-debuginfoUpgrade samba-libs-debuginfo-32bitUpgrade libdcerpc0-debuginfoUpgrade samba-debugsourceUpgrade libsamdb0-32bitUpgrade libndr-nbt0-32bitUpgrade libdcerpc-atsvc0-debuginfoUpgrade libnetapi0-32bitUpgrade libsamba-util0Upgrade libtevent-util0-debuginfo-32bitUpgrade libdcerpc0Upgrade libsamdb0Upgrade ctdb-testsUpgrade libnetapi-develUpgrade libndr-krb5pac-develUpgrade libsamba-errors-develUpgrade libsmbconf0-debuginfo-32bitUpgrade libtevent-util0-32bitUpgrade libndr0-32bitUpgrade libsamba-credentials0-32bitUpgrade libndr-standard0-debuginfo-32bitUpgrade libndr-nbt0-debuginfoUpgrade libsamdb-develUpgrade libsamba-passdb0-debuginfo-32bitUpgrade libdcerpc-binding0-32bitUpgrade samba-winbind-debuginfo-32bitUpgrade samba-debuginfo-32bitUpgrade libsmbldap2Upgrade libsamba-policy0-debuginfoUpgrade libtevent-util0-debuginfoUpgrade libsamba-hostconfig0-debuginfo-32bitUpgrade libdcerpc-samr0-debuginfoUpgrade libsamdb0-debuginfoUpgrade libsmbclient0-debuginfoUpgrade libregistry0-debuginfo-32bitUpgrade libsmbconf0Upgrade libsmbclient0-debuginfo-32bitUpgrade libsamba-policy0-32bitUpgrade libsmbclient0Upgrade libndr-develUpgrade libgensec0-debuginfoUpgrade libnetapi0-debuginfo-32bitUpgrade libsmbclient-raw0-32bitUpgrade libsamba-util0-debuginfo-32bitUpgrade samba-testUpgrade libsamba-errors0Upgrade libsmbldap0-debuginfo-32bitUpgrade libsmbconf-develUpgrade libwbclient0-32bitUpgrade libsamdb0-debuginfo-32bitUpgrade libwbclient-develUpgrade libsmbldap0Upgrade libregistry0-debuginfoUpgrade samba-pidlUpgrade libsamba-passdb0Upgrade libsmbconf0-32bitUpgrade libregistry0Upgrade libsmbclient-raw0Upgrade libsmbldap-develUpgrade samba-test-develUpgrade libtevent-util-develUpgrade libregistry-develUpgrade libsmbclient-raw0-debuginfo-32bitUpgrade libsmbclient-raw-develUpgrade libsamba-credentials0-debuginfoUpgrade samba-docUpgrade libsamba-passdb-develUpgrade libdcerpc-binding0-debuginfo-32bitUpgrade libndr-krb5pac0-debuginfoUpgrade libregistry0-32bitUpgrade libnetapi0-debuginfoUpgrade libdcerpc0-debuginfo-32bitUpgrade libwbclient0-debuginfo-32bitUpgrade libsamba-hostconfig0Upgrade libgensec0-debuginfo-32bitUpgrade samba-test-debuginfoUpgrade libdcerpc-samr-develUpgrade samba-libs-32bitUpgrade samba-32bitUpgrade samba-winbind-debuginfoUpgrade libndr-standard0-debuginfoUpgrade libdcerpc-samr0-32bitUpgrade libsamba-errors0-debuginfo-32bitUpgrade libsamba-credentials0Upgrade samba-libs-debuginfoUpgrade samba-libsUpgrade libndr-standard0-32bitUpgrade samba-client-debuginfoUpgrade libsamba-credentials-develUpgrade libndr-standard0Upgrade samba-client-debuginfo-32bitUpgrade libdcerpc-atsvc0-debuginfo-32bitUpgrade samba-dsdb-modulesUpgrade samba-debuginfoUpgrade ctdbUpgrade samba-libs-python3Upgrade libgensec-develUpgrade samba-winbindUpgrade libsamba-policy0Upgrade libndr-standard-develUpgrade libsmbldap0-debuginfoUpgrade libsamba-util0-debuginfoUpgrade libndr-krb5pac0-debuginfo-32bitUpgrade libwbclient0Upgrade libtevent-util0Upgrade libnetapi0Upgrade libsamba-policy-develUpgrade samba-client-32bitUpgrade libsmbclient-raw0-debuginfoUpgrade libdcerpc-binding0Upgrade libwbclient0-debuginfoUpgrade libndr-krb5pac0-32bitUpgrade libsmbclient0-32bitUpgrade libndr-nbt0Upgrade libsmbldap0-32bitUpgrade libndr0-debuginfoUpgrade libndr-nbt-develUpgrade libsamba-passdb0-debuginfoUpgrade libsamba-errors0-debuginfoUpgrade samba-python-debuginfoUpgrade libdcerpc-develUpgrade libsmbldap2-32bitUpgrade libsamba-errors0-32bitUpgrade libndr-nbt0-debuginfo-32bitUpgrade sambaUpgrade samba-kdcUpgrade libsamba-credentials0-debuginfo-32bitUpgrade libsamba-util0-32bitUpgrade libsamba-util-develUpgrade libsamba-policy0-debuginfo-32bitUpgrade samba-clientUpgrade samba-winbind-32bitUpgrade libdcerpc-atsvc0-32bitUpgrade libsmbclient-develUpgrade samba-pythonUpgrade libdcerpc0-32bit | Dec 28, 2016 | Dec 19, 2016 |
| Ubuntu | — | Upgrade winbindUpgrade sambaUpgrade libsmbclient | Dec 20, 2016 | Dec 19, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub