CVE-2021-3671: Null Pointer Dereference
A null pointer de-reference was found in the way samba kerberos server handled missing sname in TGS-REQ (Ticket Granting Server - Request). An authenticated user could use this flaw to crash the samba server.
Other sources
Samba's use of Heimdal was vulnerable to a null pointer de-reference flaw due to missing sname in TGS-REQ.
This is already fixed in upstream Heimdal via: https://github.com/heimdal/heimdal/commit/04171147948d0a3636bc6374181926f0fb2ec83a
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/heimdalto a version that resolves this vulnerability.Fixed in 7.7.0+dfsg-3Fixed in 7.7.0+dfsg-2+deb11u1 - Upgrade
Upgrade
redhat/sambato a version that resolves this vulnerability.Fixed in 4.13.12 - Upgrade
Upgrade
redhat/sambato a version that resolves this vulnerability.Fixed in 4.14.8 - Upgrade
Upgrade
debian/heimdalto a version that resolves this vulnerability.Fixed in 7.7.0+dfsg-2+deb11u3Fixed in 7.8.git20221117.28daf24+dfsg-2Fixed in 7.8.git20221117.28daf24+dfsg-8 - Upgrade
Upgrade
debian/sambato a version that resolves this vulnerability.Fixed in 2:4.13.13+dfsg-1~deb11u6Fixed in 2:4.17.12+dfsg-0+deb12u1Fixed in 2:4.21.1+dfsg-2 - Upgrade
Upgrade
heimdal/heimdalto a version that resolves this vulnerability.Patch 04171147948d0a3636bc6374181926f0fb2ec83a
Event History
Frequently Asked Questions
What is the vulnerability ID?
CVE-2021-3671
What is the severity of CVE-2021-3671?
The severity of CVE-2021-3671 is medium.
What is the description of CVE-2021-3671?
CVE-2021-3671 is a vulnerability in the samba kerberos server where a null pointer de-reference can allow an authenticated user to crash the server.
Which software is affected by CVE-2021-3671?
The affected software includes Ubuntu's heimdal package versions 1.6~ (trusty), 7.7.0+dfsg-3 (heimdal/upstream), 7.5.0+dfsg-1ubuntu0.1 (bionic), 7.7.0+dfsg-1ubuntu1.1 (focal), 1.7~ (xenial); Ubuntu's samba package versions 2:4.13.14+dfsg-0ubuntu0.21.10.1 (impish), 4.13.13 (upstream), 2:4.13.14+dfsg-0ubuntu0.20.04.1 (focal), 2:4.13.14+dfsg-0ubuntu0.21.04.1 (hirsute), 2:4.7.6+dfsg~ubuntu-0ubuntu2.26 (bionic), 2:4.13.14+dfsg-0ubuntu1 (jammy), 2:4.13.14+dfsg-0ubuntu1 (kinetic), 2:4.13.14+dfsg-0ubuntu1 (lunar); Red Hat's samba package versions 4.13.12, 4.14.8; Debian's heimdal package versions 7.5.0+dfsg-3+deb10u2, 7.7.0+dfsg-2+deb11u3, 7.8.git20221117.28daf24+dfsg-2, 7.8.git20221117.28daf24+dfsg-3; Debian's samba package versions 2:4.13.13+dfsg-1~deb11u5, 2:4.17.9+dfsg-0+deb12u3, 2:4.17.10+dfsg-0+deb12u1, 2:4.19.0+dfsg-1.
Are there any references for CVE-2021-3671?
Yes, there are references available for CVE-2021-3671. They can be found at the following URLs: https://bugzilla.redhat.com/show_bug.cgi?id=2013080, https://bugzilla.samba.org/show_bug.cgi?id=14770, https://github.com/heimdal/heimdal/commit/04171147948d0a3636bc6374181926f0fb2ec83a