CVE-2019-12435: Null Pointer Dereference
Last updated 25 August 2025
Other sources
Samba 4.9.x before 4.9.9 and 4.10.x before 4.10.5 has a NULL pointer dereference, leading to Denial of Service. This is related to the AD DC DNS management server (dnsserver) RPC server process.
— Launchpad
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-12435?
CVE-2019-12435 is a vulnerability in Samba 4.9.x before 4.9.9 and 4.10.x before 4.10.5 that allows for a NULL pointer dereference, leading to denial of service.
What is the severity of CVE-2019-12435?
The severity of CVE-2019-12435 is medium (6.5).
How does CVE-2019-12435 affect Samba?
CVE-2019-12435 affects Samba versions 4.9.x before 4.9.9 and 4.10.x before 4.10.5, specifically the AD DC DNS management server (dnsserver) RPC server process.
How can I fix CVE-2019-12435?
To fix CVE-2019-12435, update Samba to version 4.9.10 or higher for Samba 4.9.x, and version 4.10.6 or higher for Samba 4.10.x.
Where can I find more information about CVE-2019-12435?
You can find more information about CVE-2019-12435 in these references: [Link 1](http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00023.html), [Link 2](http://www.securityfocus.com/bid/108825), [Link 3](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QSG3TLPZP35RH5DWAIDC7MHXRK5DFKOE/).