First published: Tue Aug 30 2022(Updated: )
In Samba, GnuTLS gnutls_rnd() can fail and give predictable random values.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Samba Samba | >=4.1.0 | |
Fedoraproject Fedora | =37 | |
redhat/samba | <4.17 | 4.17 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-1615 is a vulnerability in Samba where GnuTLS gnutls_rnd() can fail and give predictable random values.
The severity of CVE-2022-1615 is medium with a CVSS score of 5.5.
Samba versions 4.1.0 and above, as well as Fedora 37, are affected by CVE-2022-1615.
To fix CVE-2022-1615, it is recommended to update Samba to a patched version or apply the necessary updates provided by the distribution.
More information about CVE-2022-1615 can be found in the following references: [Bugzilla](https://bugzilla.samba.org/show_bug.cgi?id=15103), [GitLab](https://gitlab.com/samba-team/samba/-/merge_requests/2644), [Fedora Mailing List](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZTTOLTHUHOV4SHCHCB5TAA4FQVJAWN4P/)