You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
CVE-2021-44142: The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "...enhanced compatibility with Apple SMB clients and interoperability with a Netatalk 3 AFP fileserver." Samba versions prior to 4.13.17, 4.14.12 and 4.15.5 with vfs_fruit configured allow out-of-bounds heap read and write via specially crafted extended file attributes. A remote attacker with write access to extended file attributes can execute arbitrary code with the privileges of smbd, typically root.
CVE-2022-1615: In Samba, GnuTLS gnutls_rnd() can fail and give predictable random values.
See also https://security.gentoo.org/glsa/202309-06.
(Note: That GLSA entry has 34 different CVEs, but only 2 affects Flatcar. In most cases they affect smbd, AD & DC, which are disabled in Flatcar. However, there were actually 2 rare cases that affect Flatcar, one in a vfs module, the other in lib.)
Name: samba
CVEs: CVE-2021-44142, CVE-2022-1615
CVSSs: 8.8, 5.5
Action Needed: update to >= 4.17.5
Summary:
See also https://security.gentoo.org/glsa/202309-06.
(Note: That GLSA entry has 34 different CVEs, but only 2 affects Flatcar. In most cases they affect smbd, AD & DC, which are disabled in Flatcar. However, there were actually 2 rare cases that affect Flatcar, one in a vfs module, the other in lib.)
refmap.gentoo:
The text was updated successfully, but these errors were encountered: