← back
CVE-2021-44142highobserved exploitationCWE-125CWE-787

CVE-2021-44142

85Vexday Risk Score

Prioritize patching. It exploitation observed by VulnCheck and has a public proof of concept.

ssvc Actcvss 8.8epss 73%
from disclosure to weapon36 days
Published on NVDFeb 21
1st PoC+36d
VulnCheck+885d
exploitation probability
73%top 1% of all CVEs
observed exploitation
yesVulnCheck
2 public exploit(s)
What the vendors declare (VEX)

Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.

Fixed
31 products (1,694 components)
Red Hat Enterprise Linux BaseOS EUS (v.8.4) · Red Hat Enterprise Linux BaseOS EUS (v. 8.2) · Red Hat Enterprise Linux BaseOS (v. 8) · Red Hat Enterprise Linux CRB EUS (v.8.4) · Red Hat CodeReady Linux Builder (v. 8) · and others 26
Not affected
3 products (71 components) — because the vulnerable code is not present in the product
Red Hat Enterprise Linux 9 · Red Hat Enterprise Linux 6 · Red Hat Virtualization 4
In short

Samba's vfs_fruit module has a vulnerability in how it handles special file attributes, allowing attackers with write access to read and write beyond memory boundaries. This can lead to arbitrary code execution with root privileges on affected systems.

Technical detail

The vfs_fruit module in Samba versions before 4.13.17, 4.14.12, and 4.15.5 improperly validates extended file attributes (xattr), enabling out-of-bounds heap read/write operations (CWE-125, CWE-787). An authenticated remote attacker with write access to xattr can craft malicious attributes to trigger heap buffer overflow, achieving arbitrary code execution in the smbd process context.

Summary generated and translated by AI from the official description.
The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "...enhanced compatibility with Apple SMB clients and interoperability with a Netatalk 3 AFP fileserver." Samba versions prior to 4.13.17, 4.14.12 and 4.15.5 with vfs_fruit configured allow out-of-bounds heap read and write via specially crafted extended file attributes. A remote attacker with write access to extended file attributes can execute arbitrary code with the privileges of smbd, typically root.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
Samba · Samba
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.