HomeSambaCVE-2021-44142

CVE-2021-44142

HIGH
8.8CVSS
Published: 2022-02-21
Updated: 2025-04-23
AI Analysis

Description

The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "...enhanced compatibility with Apple SMB clients and interoperability with a Netatalk 3 AFP fileserver." Samba versions prior to 4.13.17, 4.14.12 and 4.15.5 with vfs_fruit configured allow out-of-bounds heap read and write via specially crafted extended file attributes. A remote attacker with write access to extended file attributes can execute arbitrary code with the privileges of smbd, typically root.

CVSS Metrics

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
network
Complexity
low
Privileges
low
User Action
none
Scope
unchanged
Confidentiality
high
Integrity
high
Availability
high
Weaknesses
CWE-125CWE-787CWE-125CWE-787

Metadata

Primary Vendor
SAMBA
Published
2/21/2022
Last Modified
4/23/2025
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

samba : sambasamba : sambasamba : sambadebian : debian_linuxdebian : debian_linuxcanonical : ubuntu_linuxcanonical : ubuntu_linuxcanonical : ubuntu_linuxcanonical : ubuntu_linuxcanonical : ubuntu_linuxsynology : diskstation_managerfedoraproject : fedorafedoraproject : fedoraredhat : codeready_linux_builderredhat : gluster_storageredhat : virtualization_hostredhat : enterprise_linuxredhat : enterprise_linuxredhat : enterprise_linux_desktopredhat : enterprise_linux_eusredhat : enterprise_linux_eusredhat : enterprise_linux_for_ibm_z_systemsredhat : enterprise_linux_for_ibm_z_systemsredhat : enterprise_linux_for_ibm_z_systems_eusredhat : enterprise_linux_for_ibm_z_systems_eusredhat : enterprise_linux_for_power_big_endianredhat : enterprise_linux_for_power_little_endianredhat : enterprise_linux_for_power_little_endianredhat : enterprise_linux_for_power_little_endian_eusredhat : enterprise_linux_for_power_little_endian_eusredhat : enterprise_linux_for_scientific_computingredhat : enterprise_linux_resilient_storageredhat : enterprise_linux_serverredhat : enterprise_linux_serverredhat : enterprise_linux_server_ausredhat : enterprise_linux_server_ausredhat : enterprise_linux_server_tusredhat : enterprise_linux_server_tusredhat : enterprise_linux_server_update_services_for_sap_solutionsredhat : enterprise_linux_server_update_services_for_sap_solutionsredhat : enterprise_linux_server_update_services_for_sap_solutionsredhat : enterprise_linux_workstation

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief

CVE-CVE-2021-44142 | HIGH Severity | CVEDatabase.com | CVEDatabase.com