Impact
A vulnerability in Samba's pam_winbind allows the mkhomedir feature to change ownership of the target account's home directory without verifying that the path is not a is system accounts) is used, even a non‑root user with limited sudo authority can trigger the chown, be altered. Since root ownership of / is required for normal system operation, this results in a severe denial of service, disabling SSH, sudo, and package management, but does not provide additional privilege escalation. The flaw is a CWE-732 weakness—Incorrect Permission Assignment for Critical Resource.
Affected Systems
The flaw affects Red Hat Enterprise Linux distributions 6 through 10 that use Samba RHEL 6, 7, 8, 9, and 10 enabled this feature are vulnerable, regardless of Samba version mentioned in the references.
Risk and Exploitability
The CVSS score of 6.1 reflects a moderate severity, and the EPSS score of less than 1% indicates a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a non‑root user with limited sudo authority that can run commands as a system account with a home directory of /. This inference is drawn from the description, which notes that the flaw can be triggered by a non‑root user holding a narrow sudo delegation. Because the impact is loss of availability rather than elevation of privilege, an attacker would target services that depend on normal ownership of the root path, but the description does not explicitly state the attack vector.
OpenCVE Enrichment
Ubuntu USN