{"id":"GSD-2021-44142","summary":"Remote code execution as root in Samba prior to version 4.13.17","details":"To quote the Samba advisory: \n\n All versions of Samba prior to 4.13.17 are vulnerable to an out-of-bounds heap read write vulnerability that allows remote attackers to execute arbitrary code as root on affected Samba installations that use the VFS module vfs_fruit. \n\n The specific flaw exists within the parsing of EA metadata when opening files in smbd. Access as a user that has write access to a file's extended attributes is required to exploit this vulnerability. Note that this could be a guest or unauthenticated user if such users are allowed write access to file extended attributes. \n\n The problem in vfs_fruit exists in the default configuration of the fruit VFS module using fruit:metadata=netatalk or fruit:resource=file. If both options are set to different settings than the default values, the system is not affected by the security issue.","modified":"2026-02-23T02:58:39.561203Z","published":"2022-02-01T23:00:11.123456Z","references":[{"url":"https://www.samba.org/samba/security/CVE-2021-44142.html"},{"url":"https://access.redhat.com/security/cve/cve-2021-44142"},{"url":"https://ubuntu.com/security/CVE-2021-44142"},{"url":"https://ubuntu.com/security/notices/USN-5260-1"},{"url":"https://ubuntu.com/security/notices/USN-5260-2"},{"url":"https://www.synology.com/en-us/security/advisory/Synology_SA_22_02"},{"url":"https://support.f5.com/csp/article/K84695749"},{"type":"WEB","url":"https://www.zerodayinitiative.com/blog/2022/2/1/cve-2021-44142-details-on-a-samba-code-execution-bug-demonstrated-at-pwn2own-austin"},{"type":"WEB","url":"https://www.whitesourcesoftware.com/resources/blog/samba-vulnerability-cve-2021-44142/"},{"type":"WEB","url":"https://www.theregister.com/2022/02/02/samba_vfs_fruit_vulnerability/"}],"schema_version":"1.7.3"}