RHSA-2021:5192: Important: samba security and bug fix update
Samba is an open-source implementation of the Server Message Block (SMB) protocol and the related Common Internet File System (CIFS) protocol, which allow PC-compatible machines to share files, printers, and various information.<br>Security Fix(es):<br><li> samba: Active Directory (AD) domain user could become root on domain members (CVE-2020-25717)</li> <li> samba: SMB1 client connections can be downgraded to plaintext authentication (CVE-2016-2124)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.<br>Bug Fix(es):<br><li> Backport IDL changes to harden Kerberos communication (BZ#2021428)</li>
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2021:5192?
The severity of RHSA-2021:5192 is critical due to vulnerabilities in Samba that could lead to remote code execution or denial of service.
How do I fix RHSA-2021:5192?
To fix RHSA-2021:5192, you should upgrade the Samba packages to the specified version 4.10.16-17.el7_9 or later.
What versions are affected by RHSA-2021:5192?
RHSA-2021:5192 affects Samba version prior to 4.10.16-17.el7_9.
Is there a workaround for RHSA-2021:5192?
There are no specific workarounds recommended for RHSA-2021:5192; it's advised to apply the security update.
What components are related to RHSA-2021:5192?
RHSA-2021:5192 relates to several components including samba, libsmbclient, and their respective development packages.