Integer overflow in Samba - CVE-2022-42898
Published: November 15, 2022
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code on the target system.
The vulnerability exists due to an integer overflow within the S4U2Proxy handler on 32-bit systems. A remote user can send specially crafted request to the KDC server, trigger an integer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Amazon Linux AMI
Debian Linux
Gentoo Linux
Oracle Linux
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro
openSUSE Leap Micro
Red Hat Enterprise Linux Server - Extended Life Cycle Support
Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems)
SUSE Enterprise Storage
CentOS
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Fedora
Anolis OS
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
Oracle Solaris
FreeBSD
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise High Availability
Ubuntu
Slackware Linux
SUSE Linux Enterprise Realtime Extension
SUSE Linux Enterprise Module for Python2
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Module for Server Applications
openSUSE Leap
openEuler
Dell Data Protection Central
Dell EMC PowerProtect Data Protection
IBM Cloud Pak for Watson AIOps
HP-UX Common Internet File System (CIFS)
cflinuxfs3
ObjectScale
Cloud Pak for Network Automation
PowerStore T
Platform Automation Toolkit
XtremIO X2
IBM supplied MQ Advanced container images
Security Verify Governance - Identity Manager virtual appliance
EMC Cloud Tiering Appliance
Dell PowerProtect Cyber Recovery
Robotic Process Automation for Cloud Pak
EMC Integrated Data Protection Appliance
VMware Tanzu Application Service for VMs
Isolation Segment
Submariner
NetObserv Operator
Data Lakehouse
Migration Toolkit for Runtimes
Service Telemetry Framework
Ansible Automation Platform
Migration Toolkit for Virtualization
Red Hat Advanced Cluster Management for Kubernetes
Red Hat Advanced Cluster Security for Kubernetes
Oracle VM Server for x86
OpenShift Logging
Splunk User Behavior Analytics (UBA)
Red Hat Migration Toolkit for Applications
Oracle Communications Diameter Signaling Router
Oracle Communications Cloud Native Core Binding Support Function
Oracle Communications Cloud Native Core Network Repository Function
Oracle Communications Network Analytics Data Director
Netcool Operations Insight
IBM MQ Operator
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
App Connect Enterprise Certified Container
Dell Secure Connect Gateway
QVP (QVR Pro appliances)
heimdal
Secondary Scheduler Operator for Red Hat OpenShift (OSSO)
OpenShift API for Data Protection (OADP)
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
IBM Edge Application Manager
OpenShift Service Mesh
Red Hat Virtualization
Red Hat OpenShift Serverless
VMware Tanzu Operations Manager
OpenShift Virtualization
OpenShift Data Foundation (formerly OpenShift Container Storage)
Red Hat Virtualization Host
MySQL Cluster
Oracle Healthcare Translational Research
OpenShift Developer Tools and Services
RecoverPoint for Virtual Machines
IBM Qradar SIEM
Cloud Pak for Security (CP4S)
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
libkdb5-7 (Ubuntu package)
libkdb5-8 (Ubuntu package)
libgssapi3-heimdal (Ubuntu package)
libhdb9-heimdal (Ubuntu package)
libasn1-8-heimdal (Ubuntu package)
libkrb5-26-heimdal (Ubuntu package)
libhx509-5-heimdal (Ubuntu package)
krb5-admin-server (Ubuntu package)
krb5-user (Ubuntu package)
libgssapi-krb5-2 (Ubuntu package)
krb5-kdc (Ubuntu package)
krb5 (Red Hat package)
krb5-devel
krb5-server-debuginfo
krb5-server
krb5-plugin-preauth-pkinit-debuginfo
krb5-plugin-preauth-pkinit
krb5-plugin-preauth-otp-debuginfo
krb5-plugin-preauth-otp
krb5-plugin-kdb-ldap-debuginfo
krb5-doc
krb5-debugsource
krb5-debuginfo-32bit
krb5-debuginfo
krb5-client-debuginfo
krb5-client
krb5-32bit
krb5
krb5-plugin-kdb-ldap
krb5-libs
krb5-pkinit
krb5-server-ldap
krb5-workstation
libkadm5
krb5-32bit-debuginfo
libkdb5-9 (Ubuntu package)
krb5 (Debian package)
libkdb5-10 (Ubuntu package)
krb5-mini
krb5-mini-debuginfo
krb5-mini-debugsource
krb5-mini-devel
krb5-plugin-preauth-spake
krb5-plugin-preauth-spake-debuginfo
krb5-devel-32bit
app-crypt/mit-krb5
samba (Ubuntu package)
redhat-virtualization-host-productimg (Red Hat package)
redhat-release-virtualization-host (Red Hat package)
samba-common
samba-dc-bind-dlz
samba-winbind
samba-dc
python3-samba-test
ctdb
samba-krb5-printing
libwbclient
libsmbclient-devel
samba-winbind-clients
samba
samba-common-tools
samba-winbind-krb5-locator
samba-client
samba-debuginfo
samba-pidl
samba-libs
samba-winbind-modules
samba-debugsource
samba-dc-provision
python3-samba
libwbclient-devel
samba-help
samba-test
ctdb-tests
samba-devel
python3-samba-dc
libsmbclient
samba-vfs-glusterfs
samba-libs-python3-debuginfo
samba-ad-dc
samba-ldb-ldap-debuginfo
samba-ldb-ldap
libsamba-policy0-python3-32bit
samba-gpupdate
samba-dsdb-modules-debuginfo
samba-dsdb-modules
samba-client-debuginfo
libsamba-policy0-python3
samba-ad-dc-libs-debuginfo
libsamba-policy0-python3-debuginfo
samba-ad-dc-libs
samba-ad-dc-debuginfo
samba-winbind-debuginfo
samba-ceph-debuginfo
libsamba-policy0-python3-64bit
libsamba-policy0-python3-64bit-debuginfo
samba-client-64bit
samba-client-64bit-debuginfo
samba-libs-64bit
samba-ceph
samba-winbind-libs-debuginfo
samba-winbind-libs
samba-tool
samba-test-debuginfo
samba-python3-debuginfo
samba-python3
samba-libs-python3
samba-libs-debuginfo
samba-libs-64bit-debuginfo
samba-client-libs
samba-client-libs-debuginfo
ctdb-debuginfo
ctdb-pcp-pmda
ctdb-pcp-pmda-debuginfo
libsamba-policy-devel
samba-winbind-libs-32bit-debuginfo
samba-winbind-libs-32bit
samba-libs-python3-32bit-debuginfo
samba-libs-python3-32bit
samba-libs-32bit-debuginfo
samba-devel-32bit
samba-libs-python3-64bit
samba-libs-python3-64bit-debuginfo
samba-doc
libsamba-policy-python3-devel
libsamba-policy0-python3-32bit-debuginfo
samba-ad-dc-libs-32bit
samba-ad-dc-libs-32bit-debuginfo
samba-client-32bit
samba-client-32bit-debuginfo
samba-client-libs-32bit
samba-client-libs-32bit-debuginfo
samba-libs-32bit
samba-winbind-libs-debuginfo-32bit
samba-libs-python3-debuginfo-32bit
samba-libs-debuginfo-32bit
samba-client-libs-debuginfo-32bit
samba-client-debuginfo-32bit
libsamba-policy0-python3-debuginfo-32bit
net-fs/samba
heimdal (Debian package)
heimdal
IBM Security Guardium
Oracle Communications Cloud Native Core Security Edge Protection Proxy
Voice Gateway
EMC ViPR SRM
Dell EMC Storage Monitoring and Reporting (SMR)
QNAP QTS
Dell EMC VxRail Appliance
Juniper Junos Space
How to mitigate CVE-2022-42898
Submariner - update to 0.14.0
NetObserv Operator - update to 1.1.0
heimdal - update to 7.7.1
Secondary Scheduler Operator for Red Hat OpenShift (OSSO) - update to 1.1.1
Data Lakehouse - update to 1.1.0.0
Migration Toolkit for Runtimes - update to 1.0.1
OpenShift API for Data Protection (OADP) - update to 1.1.2
Service Telemetry Framework - update to 1.5.2
Migration Toolkit for Containers - addressed in versions 1.7.6, 1.7.10
OpenShift Service Mesh - update to 2.3.1
Migration Toolkit for Virtualization - update to 2.4.3
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.6.3, 2.6.4
Red Hat Advanced Cluster Security for Kubernetes - update to 3.73
Red Hat OpenShift Container Platform - addressed in versions 4.11.20, 4.11.45, 4.12.0, 4.13.0
OpenShift Developer Tools and Services - update to 4.9
OpenShift Logging - addressed in versions 5.3.14, 5.6.1
Splunk User Behavior Analytics (UBA) - update to 5.4.3
Red Hat Migration Toolkit for Applications - update to 6.0.1
RecoverPoint for Virtual Machines - update to 6.0 SP2 P1
IBM Qradar SIEM - addressed in versions 7.4.3 Fix Pack 9, 7.5.0 Update Pack 5 IF01
libkdb5-7 (Ubuntu package) - update to Ubuntu Pro (Infra-only)
libkdb5-8 (Ubuntu package) - update to Ubuntu Pro (Infra-only)
libgssapi3-heimdal (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 7.5.0+dfsg-1ubuntu0.3, 7.7.0+dfsg-1ubuntu1.3
libhdb9-heimdal (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 7.5.0+dfsg-1ubuntu0.3, 7.7.0+dfsg-1ubuntu1.3
libasn1-8-heimdal (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 7.5.0+dfsg-1ubuntu0.3, 7.7.0+dfsg-1ubuntu1.3
libkrb5-26-heimdal (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 7.5.0+dfsg-1ubuntu0.3, 7.7.0+dfsg-1ubuntu1.3
libhx509-5-heimdal (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 7.5.0+dfsg-1ubuntu0.3, 7.7.0+dfsg-1ubuntu1.3
krb5-admin-server (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 1.16-2ubuntu0.3, 1.17-6ubuntu4.2, 1.19.2-2ubuntu0.1, 1.20-1ubuntu0.1
krb5-user (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 1.16-2ubuntu0.3, 1.17-6ubuntu4.2, 1.19.2-2ubuntu0.1, 1.20-1ubuntu0.1
libgssapi-krb5-2 (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 1.16-2ubuntu0.3, 1.17-6ubuntu4.2, 1.19.2-2ubuntu0.1, 1.20-1ubuntu0.1
krb5-kdc (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 1.16-2ubuntu0.3, 1.17-6ubuntu4.2, 1.19.2-2ubuntu0.1, 1.20-1ubuntu0.1
HP-UX Common Internet File System (CIFS) - update to B.04.18.01.00
cflinuxfs3 - update to 0.349.0
Voice Gateway - addressed in versions 1.0.8.1, 1.0.8.2, 1.0.8.5
ObjectScale - update to 1.4.0
Netcool Operations Insight - update to 1.6.12
krb5 (Red Hat package) - addressed in versions 1.10.3-66.el6_10, 1.15.1-55.el7_9, 1.17-10.el8_1, 1.17-19.el8_2, 1.18.2-9.el8_4, 1.18.2-15.el8_6, 1.18.2-22.el8_7, 1.19.1-16.el9_0, 1.19.1-24.el9_1
Cloud Pak for Security (CP4S) - update to 1.10.12.0
krb5-devel - addressed in versions 1.12.5-40.43.1, 1.15.2-150000.6.17.1, 1.16.3-150100.3.27.1, 1.19.2-150300.7.7.1, 1.19.2-150300.10.1, 1.19.2-150400.3.3.1
krb5-server-debuginfo - addressed in versions 1.12.5-40.43.1, 1.15.2-150000.6.17.1, 1.16.3-150100.3.27.1, 1.19.2-150300.7.7.1, 1.19.2-150300.10.1, 1.19.2-150400.3.3.1
krb5-server - addressed in versions 1.12.5-40.43.1, 1.15.2-150000.6.17.1, 1.16.3-150100.3.27.1, 1.19.2-150300.7.7.1, 1.19.2-150300.10.1, 1.19.2-150400.3.3.1
krb5-plugin-preauth-pkinit-debuginfo - addressed in versions 1.12.5-40.43.1, 1.15.2-150000.6.17.1, 1.16.3-150100.3.27.1, 1.19.2-150300.7.7.1, 1.19.2-150300.10.1, 1.19.2-150400.3.3.1
krb5-plugin-preauth-pkinit - addressed in versions 1.12.5-40.43.1, 1.15.2-150000.6.17.1, 1.16.3-150100.3.27.1, 1.19.2-150300.7.7.1, 1.19.2-150300.10.1, 1.19.2-150400.3.3.1
krb5-plugin-preauth-otp-debuginfo - addressed in versions 1.12.5-40.43.1, 1.15.2-150000.6.17.1, 1.16.3-150100.3.27.1, 1.19.2-150300.7.7.1, 1.19.2-150300.10.1, 1.19.2-150400.3.3.1
krb5-plugin-preauth-otp - addressed in versions 1.12.5-40.43.1, 1.15.2-150000.6.17.1, 1.16.3-150100.3.27.1, 1.19.2-150300.7.7.1, 1.19.2-150300.10.1, 1.19.2-150400.3.3.1
krb5-plugin-kdb-ldap-debuginfo - addressed in versions 1.12.5-40.43.1, 1.15.2-150000.6.17.1, 1.16.3-150100.3.27.1, 1.19.2-150300.7.7.1, 1.19.2-150300.10.1, 1.19.2-150400.3.3.1
krb5-doc - update to 1.12.5-40.43.1
krb5-debugsource - addressed in versions 1.12.5-40.43.1, 1.15.2-150000.6.17.1, 1.16.3-150100.3.27.1, 1.19.2-150300.7.7.1, 1.19.2-150300.10.1, 1.19.2-150400.3.3.1
krb5-debuginfo-32bit - update to 1.12.5-40.43.1
krb5-debuginfo - addressed in versions 1.12.5-40.43.1, 1.15.2-150000.6.17.1, 1.16.3-150100.3.27.1, 1.19.2-150300.7.7.1, 1.19.2-150300.10.1, 1.19.2-150400.3.3.1
krb5-client-debuginfo - addressed in versions 1.12.5-40.43.1, 1.15.2-150000.6.17.1, 1.16.3-150100.3.27.1, 1.19.2-150300.7.7.1, 1.19.2-150300.10.1, 1.19.2-150400.3.3.1
krb5-client - addressed in versions 1.12.5-40.43.1, 1.15.2-150000.6.17.1, 1.16.3-150100.3.27.1, 1.19.2-150300.7.7.1, 1.19.2-150300.10.1, 1.19.2-150400.3.3.1
krb5-32bit - addressed in versions 1.12.5-40.43.1, 1.15.2-150000.6.17.1, 1.16.3-150100.3.27.1, 1.19.2-150300.7.7.1, 1.19.2-150300.10.1, 1.19.2-150400.3.3.1
krb5 - addressed in versions 1.12.5-40.43.1, 1.15.2-150000.6.17.1, 1.16.3-150100.3.27.1, 1.19.2-150300.7.7.1, 1.19.2-150300.10.1, 1.19.2-150400.3.3.1
krb5-plugin-kdb-ldap - addressed in versions 1.12.5-40.43.1, 1.15.2-150000.6.17.1, 1.16.3-150100.3.27.1, 1.19.2-150300.7.7.1, 1.19.2-150300.10.1, 1.19.2-150400.3.3.1
krb5 - addressed in versions 1.15.1-46.49, 1.15.1-55.51, 1.19.2-13
krb5-devel - addressed in versions 1.15.1-55.0.1, 1.18.2-22.0.1
krb5-libs - addressed in versions 1.15.1-55.0.1, 1.18.2-22.0.1
krb5-pkinit - addressed in versions 1.15.1-55.0.1, 1.18.2-22.0.1
krb5-server - addressed in versions 1.15.1-55.0.1, 1.18.2-22.0.1
krb5-server-ldap - addressed in versions 1.15.1-55.0.1, 1.18.2-22.0.1
krb5-workstation - addressed in versions 1.15.1-55.0.1, 1.18.2-22.0.1
libkadm5 - addressed in versions 1.15.1-55.0.1, 1.18.2-22.0.1
krb5-32bit-debuginfo - addressed in versions 1.15.2-150000.6.17.1, 1.16.3-150100.3.27.1, 1.19.2-150300.7.7.1, 1.19.2-150300.10.1, 1.19.2-150400.3.3.1
libkdb5-9 (Ubuntu package) - addressed in versions 1.16-2ubuntu0.3, 1.17-6ubuntu4.2
krb5-doc - update to 1.18.2-22.0.1
krb5 (Debian package) - update to 1.18.3-6+deb11u3
krb5 - update to 1.19.2
libkdb5-10 (Ubuntu package) - addressed in versions 1.19.2-2ubuntu0.1, 1.20-1ubuntu0.1
krb5 - addressed in versions 1.19.2-9.fc35, 1.19.2-12.fc36, 1.19.2-13.fc37, 1.20.1-1.fc38
krb5-mini - update to 1.19.2-150300.7.7.1
krb5-mini-debuginfo - update to 1.19.2-150300.7.7.1
krb5-mini-debugsource - update to 1.19.2-150300.7.7.1
krb5-mini-devel - update to 1.19.2-150300.7.7.1
krb5-plugin-preauth-spake - addressed in versions 1.19.2-150300.7.7.1, 1.19.2-150300.10.1, 1.19.2-150400.3.3.1
krb5-plugin-preauth-spake-debuginfo - addressed in versions 1.19.2-150300.7.7.1, 1.19.2-150300.10.1, 1.19.2-150400.3.3.1
krb5-devel-32bit - addressed in versions 1.19.2-150300.7.7.1, 1.19.2-150400.3.3.1
app-crypt/mit-krb5 - update to 1.21.2
Red Hat OpenShift Serverless - update to 1.27.0
IBM MQ Operator - addressed in versions 2.0.6, 2.2.1
Cloud Pak for Network Automation - update to 2.4.4
VMware Tanzu Operations Manager - addressed in versions 2.10.53, 3.0.4
PowerStore T - update to 3.5.0.1-2083289
samba (Ubuntu package) - addressed in versions 2:4.3.11+dfsg-0ubuntu0.14.04.20+esm13, 2:4.3.11+dfsg-0ubuntu0.14.04.20+esm14, 2:4.3.11+dfsg-0ubuntu0.16.04.34+esm2, 2:4.3.11+dfsg-0ubuntu0.16.04.34+esm3, 2:4.7.6+dfsg~ubuntu-0ubuntu2.29+esm1, 2:4.7.6+dfsg~ubuntu-0ubuntu2.29+esm2, 2:4.13.17~dfsg-0ubuntu1.20.04.4, 2:4.13.17~dfsg-0ubuntu1.20.04.5, 2:4.15.13+dfsg-0ubuntu0.20.04.1, 2:4.15.13+dfsg-0ubuntu1, 2:4.16.8+dfsg-0ubuntu1
Platform Automation Toolkit - addressed in versions 4.4.31, 5.0.24, 5.1.0
redhat-virtualization-host-productimg (Red Hat package) - update to 4.5.3-2.el8
redhat-release-virtualization-host (Red Hat package) - update to 4.5.3-2.el8ev
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.6.4
EMC ViPR SRM - update to 4.9.0.0
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.9.0.0
samba-common - update to 4.11.12-21
samba-dc-bind-dlz - update to 4.11.12-21
samba-winbind - update to 4.11.12-21
samba-dc - update to 4.11.12-21
python3-samba-test - update to 4.11.12-21
ctdb - update to 4.11.12-21
samba-krb5-printing - update to 4.11.12-21
libwbclient - update to 4.11.12-21
libsmbclient-devel - update to 4.11.12-21
samba-winbind-clients - update to 4.11.12-21
samba - update to 4.11.12-21
samba-common-tools - update to 4.11.12-21
samba-winbind-krb5-locator - update to 4.11.12-21
samba-client - update to 4.11.12-21
samba-debuginfo - update to 4.11.12-21
samba-pidl - update to 4.11.12-21
samba-libs - update to 4.11.12-21
samba-winbind-modules - update to 4.11.12-21
samba-debugsource - update to 4.11.12-21
samba-dc-provision - update to 4.11.12-21
python3-samba - update to 4.11.12-21
libwbclient-devel - update to 4.11.12-21
samba-help - update to 4.11.12-21
samba-test - update to 4.11.12-21
ctdb-tests - update to 4.11.12-21
samba-devel - update to 4.11.12-21
python3-samba-dc - update to 4.11.12-21
libsmbclient - update to 4.11.12-21
samba-vfs-glusterfs - update to 4.11.12-21
OpenShift Virtualization - update to 4.12.0
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.13.0
samba - update to 4.15.12
samba - addressed in versions 4.15.12-0.fc35, 4.16.7-0.fc36, 4.17.3-0.fc37
samba-libs-python3-debuginfo - addressed in versions 4.15.12+git.535.7750e5c95ef-150300.3.43.1, 4.15.13+git.482.1ac2c665c7-3.74.1, 4.15.13+git.591.ab36624310c-150400.3.19.1
samba-ad-dc - addressed in versions 4.15.12+git.535.7750e5c95ef-150300.3.43.1, 4.15.13+git.591.ab36624310c-150400.3.19.1
samba-ldb-ldap-debuginfo - addressed in versions 4.15.12+git.535.7750e5c95ef-150300.3.43.1, 4.15.13+git.482.1ac2c665c7-3.74.1, 4.15.13+git.591.ab36624310c-150400.3.19.1
samba-ldb-ldap - addressed in versions 4.15.12+git.535.7750e5c95ef-150300.3.43.1, 4.15.13+git.482.1ac2c665c7-3.74.1, 4.15.13+git.591.ab36624310c-150400.3.19.1
libsamba-policy0-python3-32bit - addressed in versions 4.15.12+git.535.7750e5c95ef-150300.3.43.1, 4.15.13+git.482.1ac2c665c7-3.74.1, 4.15.13+git.591.ab36624310c-150400.3.19.1
samba-gpupdate - addressed in versions 4.15.12+git.535.7750e5c95ef-150300.3.43.1, 4.15.13+git.591.ab36624310c-150400.3.19.1
samba-dsdb-modules-debuginfo - addressed in versions 4.15.12+git.535.7750e5c95ef-150300.3.43.1, 4.15.13+git.591.ab36624310c-150400.3.19.1
samba-dsdb-modules - addressed in versions 4.15.12+git.535.7750e5c95ef-150300.3.43.1, 4.15.13+git.591.ab36624310c-150400.3.19.1
samba-devel - addressed in versions 4.15.12+git.535.7750e5c95ef-150300.3.43.1, 4.15.13+git.482.1ac2c665c7-3.74.1, 4.15.13+git.591.ab36624310c-150400.3.19.1
samba-client-debuginfo - addressed in versions 4.15.12+git.535.7750e5c95ef-150300.3.43.1, 4.15.13+git.482.1ac2c665c7-3.74.1, 4.15.13+git.591.ab36624310c-150400.3.19.1
libsamba-policy0-python3 - addressed in versions 4.15.12+git.535.7750e5c95ef-150300.3.43.1, 4.15.13+git.482.1ac2c665c7-3.74.1, 4.15.13+git.591.ab36624310c-150400.3.19.1
samba-client - addressed in versions 4.15.12+git.535.7750e5c95ef-150300.3.43.1, 4.15.13+git.482.1ac2c665c7-3.74.1, 4.15.13+git.591.ab36624310c-150400.3.19.1
samba-ad-dc-libs-debuginfo - addressed in versions 4.15.12+git.535.7750e5c95ef-150300.3.43.1, 4.15.13+git.591.ab36624310c-150400.3.19.1
libsamba-policy0-python3-debuginfo - addressed in versions 4.15.12+git.535.7750e5c95ef-150300.3.43.1, 4.15.13+git.482.1ac2c665c7-3.74.1, 4.15.13+git.591.ab36624310c-150400.3.19.1
samba-ad-dc-libs - addressed in versions 4.15.12+git.535.7750e5c95ef-150300.3.43.1, 4.15.13+git.591.ab36624310c-150400.3.19.1
samba-ad-dc-debuginfo - addressed in versions 4.15.12+git.535.7750e5c95ef-150300.3.43.1, 4.15.13+git.591.ab36624310c-150400.3.19.1
samba - addressed in versions 4.15.12+git.535.7750e5c95ef-150300.3.43.1, 4.15.13+git.482.1ac2c665c7-3.74.1, 4.15.13+git.591.ab36624310c-150400.3.19.1
samba-winbind-debuginfo - addressed in versions 4.15.12+git.535.7750e5c95ef-150300.3.43.1, 4.15.13+git.482.1ac2c665c7-3.74.1, 4.15.13+git.591.ab36624310c-150400.3.19.1
samba-ceph-debuginfo - addressed in versions 4.15.12+git.535.7750e5c95ef-150300.3.43.1, 4.15.13+git.591.ab36624310c-150400.3.19.1
libsamba-policy0-python3-64bit - update to 4.15.12+git.535.7750e5c95ef-150300.3.43.1
libsamba-policy0-python3-64bit-debuginfo - update to 4.15.12+git.535.7750e5c95ef-150300.3.43.1
samba-client-64bit - update to 4.15.12+git.535.7750e5c95ef-150300.3.43.1
samba-client-64bit-debuginfo - update to 4.15.12+git.535.7750e5c95ef-150300.3.43.1
samba-libs-64bit - update to 4.15.12+git.535.7750e5c95ef-150300.3.43.1
samba-ceph - addressed in versions 4.15.12+git.535.7750e5c95ef-150300.3.43.1, 4.15.13+git.591.ab36624310c-150400.3.19.1
samba-winbind-libs-debuginfo - addressed in versions 4.15.12+git.535.7750e5c95ef-150300.3.43.1, 4.15.13+git.482.1ac2c665c7-3.74.1, 4.15.13+git.591.ab36624310c-150400.3.19.1
samba-winbind-libs - addressed in versions 4.15.12+git.535.7750e5c95ef-150300.3.43.1, 4.15.13+git.482.1ac2c665c7-3.74.1, 4.15.13+git.591.ab36624310c-150400.3.19.1
samba-libs - addressed in versions 4.15.12+git.535.7750e5c95ef-150300.3.43.1, 4.15.13+git.482.1ac2c665c7-3.74.1, 4.15.13+git.591.ab36624310c-150400.3.19.1
samba-winbind - addressed in versions 4.15.12+git.535.7750e5c95ef-150300.3.43.1, 4.15.13+git.482.1ac2c665c7-3.74.1, 4.15.13+git.591.ab36624310c-150400.3.19.1
samba-tool - addressed in versions 4.15.12+git.535.7750e5c95ef-150300.3.43.1, 4.15.13+git.482.1ac2c665c7-3.74.1, 4.15.13+git.591.ab36624310c-150400.3.19.1
samba-test-debuginfo - addressed in versions 4.15.12+git.535.7750e5c95ef-150300.3.43.1, 4.15.13+git.591.ab36624310c-150400.3.19.1
samba-test - addressed in versions 4.15.12+git.535.7750e5c95ef-150300.3.43.1, 4.15.13+git.591.ab36624310c-150400.3.19.1
samba-python3-debuginfo - addressed in versions 4.15.12+git.535.7750e5c95ef-150300.3.43.1, 4.15.13+git.482.1ac2c665c7-3.74.1, 4.15.13+git.591.ab36624310c-150400.3.19.1
samba-python3 - addressed in versions 4.15.12+git.535.7750e5c95ef-150300.3.43.1, 4.15.13+git.482.1ac2c665c7-3.74.1, 4.15.13+git.591.ab36624310c-150400.3.19.1
samba-libs-python3 - addressed in versions 4.15.12+git.535.7750e5c95ef-150300.3.43.1, 4.15.13+git.482.1ac2c665c7-3.74.1, 4.15.13+git.591.ab36624310c-150400.3.19.1
samba-libs-debuginfo - addressed in versions 4.15.12+git.535.7750e5c95ef-150300.3.43.1, 4.15.13+git.482.1ac2c665c7-3.74.1, 4.15.13+git.591.ab36624310c-150400.3.19.1
samba-libs-64bit-debuginfo - update to 4.15.12+git.535.7750e5c95ef-150300.3.43.1
samba-client-libs - addressed in versions 4.15.12+git.535.7750e5c95ef-150300.3.43.1, 4.15.13+git.482.1ac2c665c7-3.74.1, 4.15.13+git.591.ab36624310c-150400.3.19.1
samba-client-libs-debuginfo - addressed in versions 4.15.12+git.535.7750e5c95ef-150300.3.43.1, 4.15.13+git.482.1ac2c665c7-3.74.1, 4.15.13+git.591.ab36624310c-150400.3.19.1
ctdb - addressed in versions 4.15.12+git.535.7750e5c95ef-150300.3.43.1, 4.15.13+git.482.1ac2c665c7-3.74.1, 4.15.13+git.591.ab36624310c-150400.3.19.1
samba-debugsource - addressed in versions 4.15.12+git.535.7750e5c95ef-150300.3.43.1, 4.15.13+git.482.1ac2c665c7-3.74.1, 4.15.13+git.591.ab36624310c-150400.3.19.1
samba-debuginfo - addressed in versions 4.15.12+git.535.7750e5c95ef-150300.3.43.1, 4.15.13+git.482.1ac2c665c7-3.74.1, 4.15.13+git.591.ab36624310c-150400.3.19.1
ctdb-debuginfo - addressed in versions 4.15.12+git.535.7750e5c95ef-150300.3.43.1, 4.15.13+git.482.1ac2c665c7-3.74.1, 4.15.13+git.591.ab36624310c-150400.3.19.1
ctdb-pcp-pmda - addressed in versions 4.15.12+git.535.7750e5c95ef-150300.3.43.1, 4.15.13+git.591.ab36624310c-150400.3.19.1
ctdb-pcp-pmda-debuginfo - addressed in versions 4.15.12+git.535.7750e5c95ef-150300.3.43.1, 4.15.13+git.591.ab36624310c-150400.3.19.1
libsamba-policy-devel - addressed in versions 4.15.12+git.535.7750e5c95ef-150300.3.43.1, 4.15.13+git.482.1ac2c665c7-3.74.1, 4.15.13+git.591.ab36624310c-150400.3.19.1
samba-winbind-libs-32bit-debuginfo - addressed in versions 4.15.12+git.535.7750e5c95ef-150300.3.43.1, 4.15.13+git.591.ab36624310c-150400.3.19.1
samba-winbind-libs-32bit - addressed in versions 4.15.12+git.535.7750e5c95ef-150300.3.43.1, 4.15.13+git.482.1ac2c665c7-3.74.1, 4.15.13+git.591.ab36624310c-150400.3.19.1
samba-libs-python3-32bit-debuginfo - addressed in versions 4.15.12+git.535.7750e5c95ef-150300.3.43.1, 4.15.13+git.591.ab36624310c-150400.3.19.1
samba-libs-python3-32bit - addressed in versions 4.15.12+git.535.7750e5c95ef-150300.3.43.1, 4.15.13+git.482.1ac2c665c7-3.74.1, 4.15.13+git.591.ab36624310c-150400.3.19.1
samba-libs-32bit-debuginfo - addressed in versions 4.15.12+git.535.7750e5c95ef-150300.3.43.1, 4.15.13+git.591.ab36624310c-150400.3.19.1
samba-devel-32bit - addressed in versions 4.15.12+git.535.7750e5c95ef-150300.3.43.1, 4.15.13+git.482.1ac2c665c7-3.74.1, 4.15.13+git.591.ab36624310c-150400.3.19.1
samba-libs-python3-64bit - update to 4.15.12+git.535.7750e5c95ef-150300.3.43.1
samba-libs-python3-64bit-debuginfo - update to 4.15.12+git.535.7750e5c95ef-150300.3.43.1
samba-doc - addressed in versions 4.15.12+git.535.7750e5c95ef-150300.3.43.1, 4.15.13+git.482.1ac2c665c7-3.74.1, 4.15.13+git.591.ab36624310c-150400.3.19.1
libsamba-policy-python3-devel - addressed in versions 4.15.12+git.535.7750e5c95ef-150300.3.43.1, 4.15.13+git.482.1ac2c665c7-3.74.1, 4.15.13+git.591.ab36624310c-150400.3.19.1
libsamba-policy0-python3-32bit-debuginfo - addressed in versions 4.15.12+git.535.7750e5c95ef-150300.3.43.1, 4.15.13+git.591.ab36624310c-150400.3.19.1
samba-ad-dc-libs-32bit - addressed in versions 4.15.12+git.535.7750e5c95ef-150300.3.43.1, 4.15.13+git.591.ab36624310c-150400.3.19.1
samba-ad-dc-libs-32bit-debuginfo - addressed in versions 4.15.12+git.535.7750e5c95ef-150300.3.43.1, 4.15.13+git.591.ab36624310c-150400.3.19.1
samba-client-32bit - addressed in versions 4.15.12+git.535.7750e5c95ef-150300.3.43.1, 4.15.13+git.482.1ac2c665c7-3.74.1, 4.15.13+git.591.ab36624310c-150400.3.19.1
samba-client-32bit-debuginfo - addressed in versions 4.15.12+git.535.7750e5c95ef-150300.3.43.1, 4.15.13+git.591.ab36624310c-150400.3.19.1
samba-client-libs-32bit - addressed in versions 4.15.12+git.535.7750e5c95ef-150300.3.43.1, 4.15.13+git.482.1ac2c665c7-3.74.1, 4.15.13+git.591.ab36624310c-150400.3.19.1
samba-client-libs-32bit-debuginfo - addressed in versions 4.15.12+git.535.7750e5c95ef-150300.3.43.1, 4.15.13+git.591.ab36624310c-150400.3.19.1
samba-libs-32bit - addressed in versions 4.15.12+git.535.7750e5c95ef-150300.3.43.1, 4.15.13+git.482.1ac2c665c7-3.74.1, 4.15.13+git.591.ab36624310c-150400.3.19.1
samba-winbind-libs-debuginfo-32bit - update to 4.15.13+git.482.1ac2c665c7-3.74.1
samba-libs-python3-debuginfo-32bit - update to 4.15.13+git.482.1ac2c665c7-3.74.1
samba-libs-debuginfo-32bit - update to 4.15.13+git.482.1ac2c665c7-3.74.1
samba-client-libs-debuginfo-32bit - update to 4.15.13+git.482.1ac2c665c7-3.74.1
samba-client-debuginfo-32bit - update to 4.15.13+git.482.1ac2c665c7-3.74.1
libsamba-policy0-python3-debuginfo-32bit - update to 4.15.13+git.482.1ac2c665c7-3.74.1
net-fs/samba - update to 4.18.4
QNAP QTS - update to 5.0.1.2346 20230322
App Connect Enterprise Certified Container - addressed in versions 5.0.3, 7.0.0
Dell Secure Connect Gateway - update to 5.14.00.16
XtremIO X2 - update to 6.4.2-13
Dell EMC VxRail Appliance - update to 7.0.411
heimdal (Debian package) - update to 7.7.0+dfsg-2+deb11u2
heimdal - addressed in versions 7.7.1-1.el7, 7.7.1-1.el8, 7.7.1-1.fc35, 7.7.1-1.fc36, 7.7.1-1.fc37, 7.7.1-3.fc35, 7.7.1-3.fc36, 7.7.1-3.fc37
IBM supplied MQ Advanced container images - addressed in versions 9.3.0.1-r4, 9.3.1.0-r3
Security Verify Governance - Identity Manager virtual appliance - update to 10.0.2.0.4
EMC Cloud Tiering Appliance - update to 13.1.0.2.29
Dell PowerProtect Cyber Recovery - update to 19.14.0.1
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.1, 23.0.1
Juniper Junos Space - update to 23.1R1
External References
Related Security Bulletins
- Remote code execution in Samba
- Multiple vulnerabilities in Heimdal
- FreeBSD update for heimdal
- Slackware Linux update for krb5
- Slackware Linux update for samba
- Debian update for krb5
- SUSE update for krb5
- SUSE update for krb5
- SUSE update for krb5
- SUSE update for krb5
- Debian update for heimdal
- Red Hat Enterprise Linux 8 update for krb5
- Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions update for krb5
- Red Hat Enterprise Linux 7 update for krb5
- Red Hat Enterprise Linux 8.4 Extended Update Support update for krb5
- Red Hat Enterprise Linux 8 update for krb5
- Red Hat Enterprise Linux 9 update for krb5
- Red Hat Enterprise Linux 8.6 Extended Update Support update for krb5
- Red Hat Enterprise Linux 6 Extended Lifecycle Support update for krb5
- Red Hat Enterprise Linux 9.0 Extended Update Support update for krb5
- CentOS 7 update for krb5
- Multiple vulnerabilitie sin Red Hat Advanced Cluster Security (RHACS)
- SUSE update for krb5
- SUSE update for samba
- Multiple vulnerabilities in Openshift Logging 5.3
- Red Hat Virtualization 4 for RHEL 8 update for Samba
- Multiple vulnerabilities in Migration Toolkit for Containers (MTC)
- Multiple vulnerabilities in OpenShift Container Platform 4.11
- Multiple vulnerabilities in IBM Voice Gateway
- Multiple vulnerabilities in IBM MQ Operator and Queue manager container images
- SUSE update for samba
- Ubuntu update for heimdal
- Cloud Foundry Foundation cflinuxfs3 update for Heimdal
- Multiple vulnerabilities in OpenShift Container Platform 4.12
- Ubuntu update for samba
- Amazon Linux AMI update for krb5
- Multiple vulnerabilities in OpenShift Virtualization 4.12
- Ubuntu update for krb5
- SUSE update for samba
- Multiple vulnerabilities in Migration Toolkit for Runtimes
- Ubuntu update for samba
- SUSE update for krb5
- Integer overflow in IBM App Connect Enterprise Certified Container
- Multiple vulnerabilities in Red Hat OpenShift Service Mesh 2.3
- Amazon Linux AMI update for krb5
- Multiple vulnerabilities in Submariner
- Multiple vulnerabilities in OpenShift Serverless
- Multiple vulnerabilities in OpenShift Logging 5.6
- Red Hat Advanced Cluster Management for Kubernetes 2.6 update for Submariner
- Multiple vulnerabilities in NetObserv Operator
- Multiple vulnerabilities in Dell Secure Connect Gateway
- Multiple vulnerabilities in Dell Cloud Tiering Appliance
- Multiple vulnerabilities in OpenShift Developer Tools and Services
- Multiple vulnerabilities in IBM Cloud Pak for Network Automation
- Multiple vulnerabilities in Red Hat Migration Toolkit for Applications
- Ubuntu update for samba
- Multiple vulnerabilities in OpenShift API for Data Protection (OADP) 1.1
- Multiple vulnerabilities in Dell EMC VxRail Appliance
- Multiple vulnerabilities in IBM QRadar SIEM
- Remote code execution in QNAP devices running Samba
- Integer overflow in IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
- Integer overflow in IBM Security Guardium
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Security Edge Protection Proxy
- Multiple vulnerabilities in Oracle Healthcare Translational Research
- Multiple vulnerabilities in OpenShift Container Platform 4.13
- Multiple vulnerabilities in Oracle VM Server for x86
- Multiple vulnerabilities in Secondary Scheduler Operator for Red Hat OpenShift
- Multiple vulnerabilities in VMware Tanzu Platform Automation Toolkit
- Multiple vulnerabilities in IBM Cloud Pak for Security (CP4S)
- Migration Toolkit for Containers (MTC) 1.7 update for golang
- Multiple vulnerabilities in OpenShift Developer Tools and Services 4.11
- Multiple vulnerabilities in OpenShift Developer Tools and Services 4.12
- Multiple vulnerabilities in Red Hat OpenShift Data Foundation 4.13
- Multiple vulnerabilities in Oracle Solaris third-party software
- VMware Tanzu products update for Kerberos
- Multiple vulnerabilities in Juniper Junos Space
- Multiple vulnerabilities in Oracle Communications Network Analytics Data Director
- Multiple vulnerabilities in Oracle Communications Diameter Signaling Router
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Network Repository Function
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Binding Support Function
- Multiple vulnerabilities in Oracle Linux
- Multiple vulnerabilities in OpenShift Container Platform 4.11
- Multiple vulnerabilities in Dell PowerProtect Cyber Recovery
- Multiple vulnerabilities in Dell EMC SRM and Dell EMC Storage Monitoring and Reporting (SMR)
- Multiple vulnerabilities in Dell Data Protection Central
- Multiple vulnetabilities in Dell EMC Integrated Data Protection Appliance
- Multiple vulnerabilities in Dell PowerStore Family
- Gentoo update for Samba
- Integer overflow in MySQL Cluster
- Multiple vulnerabilities in IBM Cloud Pak for Watson AIOps
- Multiple vulnerabilities in Service Telemetry Framework 1.5
- Multiple vulnerabilities in Red Hat Ansible Automation Platform 2.4
- Multiple vulnerabilities in Migration Toolkit for Virtualization 2.4
- Multiple vulnerabilities in IBM Robotic Process Automation for Cloud Pak
- openEuler update for samba
- Multiple vulnerabilities in Netcool Operations Insight
- Gentoo update for MIT krb5
- Multiple vulnerabilities in Dell Data Lakehouse System Software
- Amazon Linux AMI update for krb5
- Multiple vulnerabilities in Dell ObjectScale
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.6
- Fedora 37 update for samba
- Fedora 35 update for samba
- Fedora 35 update for krb5
- Fedora 36 update for krb5
- Fedora 37 update for krb5
- Fedora 37 update for heimdal
- Fedora 36 update for heimdal
- Fedora 35 update for heimdal
- Fedora EPEL 8 update for heimdal
- Fedora EPEL 7 update for heimdal
- Fedora 36 update for samba
- Fedora 37 update for heimdal
- Fedora 35 update for heimdal
- Fedora 36 update for heimdal
- Fedora 38 update for krb5
- Multiple vulnerabilities in Dell XtremIO X2
- Multiple vulnerabilities in HP-UX Common Internet File System (CIFS)
- Multiple vulnerabilities in IBM Security Verify Governance - Identity Manager virtual appliance
- Anolis OS update for krb5
- Anolis OS update for krb5
- Dell RecoverPoint for Virtual Machines update for third-party components
- Ubuntu update for samba
- Ubuntu update for samba
- Splunk User Behavior Analytics (UBA) update for third-party components
- Multiple vulnerabilities in IBM Edge Application Manager