CVE-2022-32746: Use After Free
A flaw was found in the Samba AD LDAP server. The AD DC database audit logging module can access LDAP message values freed by a preceding database module, resulting in a use-after-free issue. This issue is only possible when modifying certain privileged attributes, such as userAccountControl.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2022-32746.
What is the severity of CVE-2022-32746?
The severity of CVE-2022-32746 is medium (5.4).
What is the affected software?
The affected software is Samba Samba versions 4.3.0 to 4.14.14, 4.15.0 to 4.15.9, and 4.16.0 to 4.16.4.
What is the description of CVE-2022-32746?
CVE-2022-32746 is a use-after-free issue in the Samba AD LDAP server, where the AD DC database audit logging module can access freed LDAP message values, resulting in a use-after-free issue when modifying certain privileged attributes.
How can I fix CVE-2022-32746?
To fix CVE-2022-32746, it is recommended to update Samba to a version that includes the fix provided by the vendor.