CVE-2016-2126: Medium severity samba vulnerability

Published Dec 9, 2016
·
Updated

As per upstream:

A remote, authenticated, attacker can cause the winbindd process to crash using a legitimate Kerberos ticket due to incorrect handling of the PAC checksum. A local service with access to the winbindd privileged pipe can cause winbindd to cache elevated access permissions.

For the remote attack, the memory overwrite kills the main winbindd process and an authenticated attacker can construct this situation by watching for password changes in Samba.

One specific trigger occurs when winbindd changes its machine account password and the client has still a valid Kerberos ticket (that was encrypted with the old password).

Other sources

Samba version 4.0.0 up to 4.5.2 is vulnerable to privilege elevation due to incorrect handling of the PAC (Privilege Attribute Certificate) checksum. A remote, authenticated, attacker can cause the winbindd process to crash using a legitimate Kerberos ticket. A local service with access to the winbindd privileged pipe can cause winbindd to cache elevated access permissions.

MITRE

Affected Software

6 affected componentsFixes available
redhat/samba<4.5.3
4.5.3
redhat/samba<4.4.8
4.4.8
redhat/samba<4.3.13
4.3.13
Samba Samba>=4.0.0<4.3.13
Samba Samba>=4.4.0<4.4.8
Samba Samba>=4.5.0<4.5.3

Event History

May 11, 2017
CVE Published
via MITRE·02:01 PM
Data Sourced
via MITRE·02:01 PM
Description

Frequently Asked Questions

1

What is the severity of CVE-2016-2126?

CVE-2016-2126 is classified as a high severity vulnerability due to its potential for privilege escalation.

2

How do I fix CVE-2016-2126?

To fix CVE-2016-2126, update Samba to version 4.5.3 or later, 4.4.8 or later, or 4.3.13 or later depending on your current version.

3

Who is affected by CVE-2016-2126?

CVE-2016-2126 affects Samba versions from 4.0.0 up to 4.5.2 across various distributions.

4

What type of attack does CVE-2016-2126 enable?

CVE-2016-2126 enables a remote, authenticated attacker to cause a denial of service by crashing the winbindd process.

5

Which component of Samba is affected by CVE-2016-2126?

CVE-2016-2126 specifically affects the winbindd process due to improper handling of the PAC checksum.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203