Impact
A flaw in Samba's clustered database service CTDB fails to verify the integrity of received protocol packets. Malformed packets containing invalid field lengths, improperly terminated strings, or inconsistent sizes can be processed without proper bounds checking. The result is that a remote actor with access to the CTDB private network can drive Samba processes to crash or consume excessive memory, leading to a denial of service. In some limited circumstances, the attacker may be able to read memory that lies adjacent to the expected packet data, potentially exposing sensitive information.
Affected Systems
Red Hat Enterprise Linux 10, 6, 7, 8, 9, and Red Hat OpenShift Container Platform 4 that run Samba with the CTDB component.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium‑severity vulnerability, and the EPSS score is not available, so the overall likelihood of exploitation remains uncertain. The vulnerability is not listed in CISA’s KEV catalog, meaning no widespread exploitation has been documented. Because the attacker must reach the CTDB private network, the venue for exploitation is limited to trusted or compromised hosts within the cluster or connected infrastructure. If such access can be obtained, the attacker can crash CTDB processes or cause high memory usage, potentially bringing affected nodes offline. In rare cases, the lack of bounds checking might also allow adjacent memory disclosure. The impact on confidentiality is limited but present, while availability is directly compromised.
OpenCVE Enrichment
Debian DSA
Ubuntu USN