Description:
Samba released security updates to address multiple vulnerabilities in Samba. For information about the vulnerabilities and the attacking vectors, please refer to the corresponding security advisories at the vendor's website.
Affected Systems:
- Samba prior to version 4.14.14, 4.15.9 and 4.16.4
It is strongly recommended to consult the product vendors if the used Linux systems are affected.
Impact:
Successful exploitation could lead to denial of service, information disclosure, privilege escalation or security restriction bypass on an affected system.
Recommendation:
Software updates or patches for affected systems are now available. Administrators of affected systems should follow the recommendations provided by the product vendor and take immediate actions to mitigate the risk.
- https://www.samba.org/samba/history/samba-4.14.14.html
- https://www.samba.org/samba/history/samba-4.15.9.html
- https://www.samba.org/samba/history/samba-4.16.4.html
The vulnerabilities are also fixed in some of the Linux distributions such as RedHat, SUSE, and Ubuntu. The following is only a sample list of Linux distributions that are affected. The list is not exhaustive and it is strongly recommended to consult the product vendors if the used Linux systems are affected. System administrators should check with their product vendors to confirm if their Linux systems are affected and the availability of patches, and if so, apply the patches or follow the recommendations provided by the product vendors to mitigate the risk.
- RedHat
- https://access.redhat.com/security/cve/CVE-2022-2031
- https://access.redhat.com/security/cve/CVE-2022-32742
- https://access.redhat.com/security/cve/CVE-2022-32744
- https://access.redhat.com/security/cve/CVE-2022-32745
- https://access.redhat.com/security/cve/CVE-2022-32746
- SUSE
- https://www.suse.com/security/cve/CVE-2022-2031.html
- https://www.suse.com/security/cve/CVE-2022-32742.html
- https://www.suse.com/security/cve/CVE-2022-32744.html
- https://www.suse.com/security/cve/CVE-2022-32745.html
- https://www.suse.com/security/cve/CVE-2022-32746.html
- Ubuntu
- https://ubuntu.com/security/CVE-2022-2031
- https://ubuntu.com/security/CVE-2022-32742
- https://ubuntu.com/security/CVE-2022-32744
- https://ubuntu.com/security/CVE-2022-32745
- https://ubuntu.com/security/CVE-2022-32746
More Information:
- https://www.samba.org/samba/security/CVE-2022-2031.html
- https://www.samba.org/samba/security/CVE-2022-32742.html
- https://www.samba.org/samba/security/CVE-2022-32744.html
- https://www.samba.org/samba/security/CVE-2022-32745.html
- https://www.samba.org/samba/security/CVE-2022-32746.html
- https://www.hkcert.org/security-bulletin/samba-multiple-vulnerabilities_20220729
- https://www.cisa.gov/uscert/ncas/current-activity/2022/07/27/samba-releases-security-updates
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2031
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-32742
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-32744 (to CVE-2022-32746)