Double-free error in Samba - CVE-2018-16841
Published: November 28, 2018
Vulnerability details
The vulnerability allows a remote authenticated attacker to cause DoS condition.
The vulnerability exists due to Samba's KDC will call talloc_free() twice on the same memory if the principal in a validly signed certificate does not match the principal in the AS-REQ when configured to accept smart-card authentication. A remote attacker can trigger double-free with talloc_free() and directly calls abort() and cause the KDC process to crash.
Affected software
Arch Linux
Debian Linux
Gentoo Linux
Slackware Linux
Fedora
busybox (Alpine package)
samba (Alpine package)
samba
How to mitigate CVE-2018-16841
samba (Alpine package) - update to 4.6.16-r2
samba - addressed in versions 4.8.7-0.fc28, 4.9.3-0.fc29