First published: Thu Aug 25 2022(Updated: )
A flaw was found in the Samba AD LDAP server. The AD DC database audit logging module can access LDAP message values freed by a preceding database module, resulting in a use-after-free issue. This issue is only possible when modifying certain privileged attributes, such as userAccountControl.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Samba Samba | >=4.3.0<4.14.14 | |
Samba Samba | >=4.15.0<4.15.9 | |
Samba Samba | >=4.16.0<4.16.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-32746.
The severity of CVE-2022-32746 is medium (5.4).
The affected software is Samba Samba versions 4.3.0 to 4.14.14, 4.15.0 to 4.15.9, and 4.16.0 to 4.16.4.
CVE-2022-32746 is a use-after-free issue in the Samba AD LDAP server, where the AD DC database audit logging module can access freed LDAP message values, resulting in a use-after-free issue when modifying certain privileged attributes.
To fix CVE-2022-32746, it is recommended to update Samba to a version that includes the fix provided by the vendor.