Skip to main content

Samba Releases Security Updates

Scheduled updates for multiple versions of Samba, including a critical vulnerability

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Scheduled updates for multiple versions of Samba, including a critical vulnerability


Threat details

Introduction

Samba has released security updates to address vulnerabilities in multiple versions of the Samba. These vulnerabilities include CVE-2021-44142, rated CVSS 9.9, which could allow an attacker to execute arbitrary code as root on affected Samba installations that use VFS module vfs_fruit. An attacker could exploit some of these vulnerabilities to take control of an affected system.


Remediation advice

Affected organisations are encouraged to review the following Samba Security Announcements and apply any relevant updates or workarounds.


Remediation steps

Type Step
Patch

Samba Security Announcement CVE-2021-44141


https://www.samba.org/samba/security/CVE-2021-44141.html
Patch

Samba Security Announcement CVE-2021-44142


https://www.samba.org/samba/security/CVE-2021-44142.html
Patch

Samba Security Announcement CVE-2022-0336


https://www.samba.org/samba/security/CVE-2022-0336.html


Last edited: 3 February 2022 3:45 pm