CVE-2022-32746
Published: 27 July 2022
A flaw was found in the Samba AD LDAP server. The AD DC database audit logging module can access LDAP message values freed by a preceding database module, resulting in a use-after-free issue. This issue is only possible when modifying certain privileged attributes, such as userAccountControl.
Notes
Author | Note |
---|---|
mdeslaur | combined patches are in bug 15096 Fixing this in Ubuntu 18.04 LTS would require substantial code backports. We will not be fixing this issue in Ubuntu 18.04 LTS. In environments where this is of concern, we recommend updating to a more recent Ubuntu version, or disabling AD DC database audit logging if this is not passible. |
Mitigation
Disabling AD DC database audit logging prevents the use-after-free from occurring, as that is the only component that will access the original message.
Priority
Status
Package | Release | Status |
---|---|---|
ldb Launchpad, Ubuntu, Debian |
impish |
Ignored
(end of life)
|
upstream |
Needs triage
|
|
focal |
Released
(2:2.2.3-0ubuntu0.20.04.3)
|
|
jammy |
Released
(2:2.4.4-0ubuntu0.1)
|
|
kinetic |
Does not exist
|
|
bionic |
Ignored
|
|
lunar |
Does not exist
|
|
samba Launchpad, Ubuntu, Debian |
trusty |
Needs triage
|
xenial |
Needs triage
|
|
impish |
Ignored
(end of life)
|
|
upstream |
Needs triage
|
|
bionic |
Ignored
|
|
focal |
Released
(2:4.13.17~dfsg-0ubuntu1.20.04.1)
|
|
jammy |
Released
(2:4.15.9+dfsg-0ubuntu0.2)
|
|
kinetic |
Released
(2:4.16.4+dfsg-2ubuntu1)
|
|
lunar |
Released
(2:4.16.4+dfsg-2ubuntu1)
|
Severity score breakdown
Parameter | Value |
---|---|
Base score | 5.4 |
Attack vector | Network |
Attack complexity | Low |
Privileges required | Low |
User interaction | None |
Scope | Unchanged |
Confidentiality | None |
Integrity impact | Low |
Availability impact | Low |
Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L |