Untriaged
Permalink
CVE-2022-2127
5.9 MEDIUM
- CVSS version: 3.1
- Attack vector (AV): NETWORK
- Attack complexity (AC): HIGH
- Privileges required (PR): NONE
- User interaction (UI): NONE
- Scope (S): UNCHANGED
- Confidentiality impact (C): NONE
- Integrity impact (I): NONE
- Availability impact (A): HIGH
Samba: out-of-bounds read in winbind auth_crap
An out-of-bounds read vulnerability was found in Samba due to insufficient length checks in winbindd_pam_auth_crap.c. When performing NTLM authentication, the client replies to cryptographic challenges back to the server. These replies have variable lengths, and Winbind fails to check the lan manager response length. When Winbind is used for NTLM authentication, a maliciously crafted request can trigger an out-of-bounds read in Winbind, possibly resulting in a crash.
References
- RHSA-2023:6667 x_refsource_REDHAT vendor-advisory
- RHSA-2023:7139 x_refsource_REDHAT vendor-advisory
- RHSA-2024:0423 x_refsource_REDHAT vendor-advisory
- https://access.redhat.com/security/cve/CVE-2022-2127 x_refsource_REDHAT vdb-entry
- RHBZ#2222791 issue-tracking x_refsource_REDHAT
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- https://security.netapp.com/advisory/ntap-20230731-0010/
- https://www.debian.org/security/2023/dsa-5477
- https://www.samba.org/samba/security/CVE-2022-2127.html
- RHSA-2023:6667 x_refsource_REDHAT vendor-advisory
- RHSA-2023:7139 x_refsource_REDHAT vendor-advisory
- RHSA-2024:0423 x_refsource_REDHAT vendor-advisory
- RHSA-2024:0580 x_refsource_REDHAT vendor-advisory
- https://access.redhat.com/security/cve/CVE-2022-2127 x_refsource_REDHAT vdb-entry
- RHBZ#2222791 issue-tracking x_refsource_REDHAT
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- https://security.netapp.com/advisory/ntap-20230731-0010/
- https://www.debian.org/security/2023/dsa-5477
- https://www.samba.org/samba/security/CVE-2022-2127.html
- RHSA-2023:6667 x_refsource_REDHAT vendor-advisory
- RHSA-2023:7139 x_refsource_REDHAT vendor-advisory
- RHSA-2024:0423 x_refsource_REDHAT vendor-advisory
- RHSA-2024:0580 x_refsource_REDHAT vendor-advisory
- https://access.redhat.com/security/cve/CVE-2022-2127 x_refsource_REDHAT vdb-entry
- RHBZ#2222791 issue-tracking x_refsource_REDHAT
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- https://security.netapp.com/advisory/ntap-20230731-0010/
- https://www.debian.org/security/2023/dsa-5477
- https://www.samba.org/samba/security/CVE-2022-2127.html
- https://lists.debian.org/debian-lts-announce/2024/04/msg00015.html
- RHSA-2023:6667 x_refsource_REDHAT vendor-advisory
- RHSA-2023:7139 x_refsource_REDHAT vendor-advisory
- RHSA-2024:0423 x_refsource_REDHAT vendor-advisory
- RHSA-2024:0580 x_refsource_REDHAT vendor-advisory
- https://access.redhat.com/security/cve/CVE-2022-2127 x_refsource_REDHAT vdb-entry
- RHBZ#2222791 issue-tracking x_refsource_REDHAT
- https://lists.debian.org/debian-lts-announce/2024/04/msg00015.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- https://security.netapp.com/advisory/ntap-20230731-0010/
- https://www.debian.org/security/2023/dsa-5477
- https://www.samba.org/samba/security/CVE-2022-2127.html
- https://access.redhat.com/security/cve/CVE-2022-2127 x_refsource_REDHAT vdb-entry
- RHBZ#2222791 issue-tracking x_refsource_REDHAT
- https://lists.debian.org/debian-lts-announce/2024/04/msg00015.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- https://security.netapp.com/advisory/ntap-20230731-0010/
- https://www.debian.org/security/2023/dsa-5477
- https://www.samba.org/samba/security/CVE-2022-2127.html
- RHSA-2023:6667 x_refsource_REDHAT vendor-advisory
- RHSA-2023:7139 x_refsource_REDHAT vendor-advisory
- RHSA-2024:0423 x_refsource_REDHAT vendor-advisory
- RHSA-2024:0580 x_refsource_REDHAT vendor-advisory
- RHSA-2023:6667 x_refsource_REDHAT vendor-advisory
- RHSA-2023:7139 x_refsource_REDHAT vendor-advisory
- RHSA-2024:0423 x_refsource_REDHAT vendor-advisory
- RHSA-2024:0580 x_refsource_REDHAT vendor-advisory
- https://access.redhat.com/security/cve/CVE-2022-2127 x_refsource_REDHAT vdb-entry
- RHBZ#2222791 issue-tracking x_refsource_REDHAT
- https://lists.debian.org/debian-lts-announce/2024/04/msg00015.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- https://security.netapp.com/advisory/ntap-20230731-0010/
- https://www.debian.org/security/2023/dsa-5477
- https://www.samba.org/samba/security/CVE-2022-2127.html
- RHSA-2023:6667 x_refsource_REDHAT vendor-advisory
- RHSA-2023:7139 x_refsource_REDHAT vendor-advisory
- RHSA-2024:0423 x_refsource_REDHAT vendor-advisory
- RHSA-2024:0580 x_refsource_REDHAT vendor-advisory
- https://access.redhat.com/security/cve/CVE-2022-2127 x_refsource_REDHAT vdb-entry
- RHBZ#2222791 issue-tracking x_refsource_REDHAT
- https://lists.debian.org/debian-lts-announce/2024/04/msg00015.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- https://security.netapp.com/advisory/ntap-20230731-0010/
- https://www.debian.org/security/2023/dsa-5477
- https://www.samba.org/samba/security/CVE-2022-2127.html
- RHSA-2023:6667 x_refsource_REDHAT vendor-advisory
- RHSA-2023:7139 x_refsource_REDHAT vendor-advisory
- RHSA-2024:0423 x_refsource_REDHAT vendor-advisory
- RHSA-2024:0580 x_refsource_REDHAT vendor-advisory
- https://access.redhat.com/security/cve/CVE-2022-2127 x_refsource_REDHAT vdb-entry
- RHBZ#2222791 issue-tracking x_refsource_REDHAT
- https://lists.debian.org/debian-lts-announce/2024/04/msg00015.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- https://security.netapp.com/advisory/ntap-20230731-0010/
- https://www.debian.org/security/2023/dsa-5477
- https://www.samba.org/samba/security/CVE-2022-2127.html
- RHSA-2023:6667 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2023:7139 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:0423 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:0580 x_refsource_REDHAT vendor-advisory x_transferred
- https://access.redhat.com/security/cve/CVE-2022-2127 x_refsource_REDHAT vdb-entry x_transferred
- RHBZ#2222791 issue-tracking x_refsource_REDHAT x_transferred
- https://lists.debian.org/debian-lts-announce/2024/04/msg00015.html x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://security.netapp.com/advisory/ntap-20230731-0010/ x_transferred
- https://www.debian.org/security/2023/dsa-5477 x_transferred
- https://www.samba.org/samba/security/CVE-2022-2127.html x_transferred
- RHSA-2023:6667 x_refsource_REDHAT vendor-advisory
- RHSA-2023:7139 x_refsource_REDHAT vendor-advisory
- RHSA-2024:0423 x_refsource_REDHAT vendor-advisory
- RHSA-2024:0580 x_refsource_REDHAT vendor-advisory
- https://access.redhat.com/security/cve/CVE-2022-2127 x_refsource_REDHAT vdb-entry
- RHBZ#2222791 issue-tracking x_refsource_REDHAT
- https://lists.debian.org/debian-lts-announce/2024/04/msg00015.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- https://security.netapp.com/advisory/ntap-20230731-0010/
- https://www.debian.org/security/2023/dsa-5477
- https://www.samba.org/samba/security/CVE-2022-2127.html
- RHSA-2023:6667 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2023:7139 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:0423 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:0580 x_refsource_REDHAT vendor-advisory x_transferred
- https://access.redhat.com/security/cve/CVE-2022-2127 x_refsource_REDHAT vdb-entry x_transferred
- RHBZ#2222791 issue-tracking x_refsource_REDHAT x_transferred
- https://lists.debian.org/debian-lts-announce/2024/04/msg00015.html x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://security.netapp.com/advisory/ntap-20230731-0010/ x_transferred
- https://www.debian.org/security/2023/dsa-5477 x_transferred
- https://www.samba.org/samba/security/CVE-2022-2127.html x_transferred
- https://www.samba.org/samba/security/CVE-2022-2127.html
- RHSA-2023:6667 x_refsource_REDHAT vendor-advisory
- RHSA-2023:7139 x_refsource_REDHAT vendor-advisory
- RHSA-2024:0423 x_refsource_REDHAT vendor-advisory
- RHSA-2024:0580 x_refsource_REDHAT vendor-advisory
- https://access.redhat.com/security/cve/CVE-2022-2127 x_refsource_REDHAT vdb-entry
- RHBZ#2222791 issue-tracking x_refsource_REDHAT
- https://lists.debian.org/debian-lts-announce/2024/04/msg00015.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- https://security.netapp.com/advisory/ntap-20230731-0010/
- https://www.debian.org/security/2023/dsa-5477
- RHSA-2023:6667 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2023:7139 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:0423 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:0580 x_refsource_REDHAT vendor-advisory x_transferred
- https://access.redhat.com/security/cve/CVE-2022-2127 x_refsource_REDHAT vdb-entry x_transferred
- RHBZ#2222791 issue-tracking x_refsource_REDHAT x_transferred
- https://lists.debian.org/debian-lts-announce/2024/04/msg00015.html x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://security.netapp.com/advisory/ntap-20230731-0010/ x_transferred
- https://www.debian.org/security/2023/dsa-5477 x_transferred
- https://www.samba.org/samba/security/CVE-2022-2127.html x_transferred
- RHSA-2023:6667 x_refsource_REDHAT vendor-advisory
- RHSA-2023:7139 x_refsource_REDHAT vendor-advisory
- RHSA-2024:0423 x_refsource_REDHAT vendor-advisory
- RHSA-2024:0580 x_refsource_REDHAT vendor-advisory
- https://access.redhat.com/security/cve/CVE-2022-2127 x_refsource_REDHAT vdb-entry
- RHBZ#2222791 issue-tracking x_refsource_REDHAT
- https://www.samba.org/samba/security/CVE-2022-2127.html
- RHSA-2024:0580 x_refsource_REDHAT vendor-advisory x_transferred
- https://access.redhat.com/security/cve/CVE-2022-2127 x_refsource_REDHAT vdb-entry x_transferred
- RHBZ#2222791 issue-tracking x_refsource_REDHAT x_transferred
- https://lists.debian.org/debian-lts-announce/2024/04/msg00015.html x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://security.netapp.com/advisory/ntap-20230731-0010/ x_transferred
- https://www.debian.org/security/2023/dsa-5477 x_transferred
- https://www.samba.org/samba/security/CVE-2022-2127.html x_transferred
- RHSA-2023:6667 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2023:7139 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:0423 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2023:6667 x_refsource_REDHAT vendor-advisory
- RHSA-2023:7139 x_refsource_REDHAT vendor-advisory
- RHSA-2024:0423 x_refsource_REDHAT vendor-advisory
- RHSA-2024:0580 x_refsource_REDHAT vendor-advisory
- https://access.redhat.com/security/cve/CVE-2022-2127 x_refsource_REDHAT vdb-entry
- RHBZ#2222791 issue-tracking x_refsource_REDHAT
- https://www.samba.org/samba/security/CVE-2022-2127.html
- RHSA-2023:6667 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2023:7139 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:0423 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:0580 x_refsource_REDHAT vendor-advisory x_transferred
- https://access.redhat.com/security/cve/CVE-2022-2127 x_refsource_REDHAT vdb-entry x_transferred
- RHBZ#2222791 issue-tracking x_refsource_REDHAT x_transferred
- https://lists.debian.org/debian-lts-announce/2024/04/msg00015.html x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://security.netapp.com/advisory/ntap-20230731-0010/ x_transferred
- https://www.debian.org/security/2023/dsa-5477 x_transferred
- https://www.samba.org/samba/security/CVE-2022-2127.html x_transferred
- RHSA-2023:6667 x_refsource_REDHAT vendor-advisory
- RHSA-2023:7139 x_refsource_REDHAT vendor-advisory
- RHSA-2024:0423 x_refsource_REDHAT vendor-advisory
- RHSA-2024:0580 x_refsource_REDHAT vendor-advisory
- https://access.redhat.com/security/cve/CVE-2022-2127 x_refsource_REDHAT vdb-entry
- RHBZ#2222791 issue-tracking x_refsource_REDHAT
- https://www.samba.org/samba/security/CVE-2022-2127.html
- RHSA-2023:6667 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2023:7139 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:0423 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:0580 x_refsource_REDHAT vendor-advisory x_transferred
- https://access.redhat.com/security/cve/CVE-2022-2127 x_refsource_REDHAT vdb-entry x_transferred
- RHBZ#2222791 issue-tracking x_refsource_REDHAT x_transferred
- https://lists.debian.org/debian-lts-announce/2024/04/msg00015.html x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://security.netapp.com/advisory/ntap-20230731-0010/ x_transferred
- https://www.debian.org/security/2023/dsa-5477 x_transferred
- https://www.samba.org/samba/security/CVE-2022-2127.html x_transferred
- RHSA-2023:6667 x_refsource_REDHAT vendor-advisory
- RHSA-2023:7139 x_refsource_REDHAT vendor-advisory
- RHSA-2024:0423 x_refsource_REDHAT vendor-advisory
- RHSA-2024:0580 x_refsource_REDHAT vendor-advisory
- https://access.redhat.com/security/cve/CVE-2022-2127 x_refsource_REDHAT vdb-entry
- RHBZ#2222791 issue-tracking x_refsource_REDHAT
- https://www.samba.org/samba/security/CVE-2022-2127.html
- https://access.redhat.com/security/cve/CVE-2022-2127 x_refsource_REDHAT vdb-entry x_transferred
- RHBZ#2222791 issue-tracking x_refsource_REDHAT x_transferred
- https://lists.debian.org/debian-lts-announce/2024/04/msg00015.html x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://security.netapp.com/advisory/ntap-20230731-0010/ x_transferred
- https://www.debian.org/security/2023/dsa-5477 x_transferred
- https://www.samba.org/samba/security/CVE-2022-2127.html x_transferred
- RHSA-2023:6667 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2023:7139 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:0423 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:0580 x_refsource_REDHAT vendor-advisory x_transferred
Affected products
samba
- ==4.17.10
- ==4.16.11
- *
- ==4.18.5
samba4
Matching in nixpkgs
pkgs.samba4
Standard Windows interoperability suite of programs for Linux and Unix
-
nixos-unstable -
- nixpkgs-unstable 4.22.3
pkgs.sambaFull
Standard Windows interoperability suite of programs for Linux and Unix
-
nixos-unstable -
- nixpkgs-unstable 4.22.3
pkgs.samba4Full
Standard Windows interoperability suite of programs for Linux and Unix
-
nixos-unstable -
- nixpkgs-unstable 4.22.3
Package maintainers
-
@aneeshusa Aneesh Agrawal <aneeshusa@gmail.com>
-
@jbedo Justin Bedő <cu@cua0.org>