Samba Releases Security Updates
Scheduled updates for multiple versions of Samba, including a critical vulnerability
Summary
Scheduled updates for multiple versions of Samba, including a critical vulnerability
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
Samba has released security updates to address vulnerabilities in multiple versions of the Samba. These vulnerabilities include CVE-2021-44142, rated CVSS 9.9, which could allow an attacker to execute arbitrary code as root on affected Samba installations that use VFS module vfs_fruit. An attacker could exploit some of these vulnerabilities to take control of an affected system.
Remediation advice
Affected organisations are encouraged to review the following Samba Security Announcements and apply any relevant updates or workarounds.
Remediation steps
| Type | Step |
|---|---|
| Patch |
Samba Security Announcement CVE-2021-44141 https://www.samba.org/samba/security/CVE-2021-44141.html |
| Patch |
Samba Security Announcement CVE-2021-44142 https://www.samba.org/samba/security/CVE-2021-44142.html |
| Patch |
Samba Security Announcement CVE-2022-0336 https://www.samba.org/samba/security/CVE-2022-0336.html |
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 3 February 2022 3:45 pm