Alibaba Cloud Linux 2.1903 Security Advisory: ALINUX2-SA-2022:0009

Issued: 2022-02-08
Updated: 2022-02-08

Summary

samba security and bug fix update

Severity

Critical

Description

Package updates are available for Alibaba Cloud Linux 2.1903 that fix the following vulnerabilities:

CVE-2021-44142:
An out-of-bounds heap read write vulnerability was found in Samba. Due to a boundary error when processing EA metadata while opening files in smbd within the VFS Samba module (vfs_fruit), a remote attacker with ability to write to file's extended attributes can trigger an out-of-bounds write and execute arbitrary code with root privileges.

References

Updated Packages