CVE-2022-38023

high
Published 2023-05-04 ยท Modified 2023-02-21
CVSS v3
โ€”
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
8.0

Description

Important: samba security update

Predictions

Exploit likelihood
20%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Red Hat Errata โ€” Red Hat Inc. ยท View original โ†— ยท Open-Errata-API

Description samba: RC4/HMAC-MD5 NetLogon Secure Channel is weak and should be avoided Red Hat statement Users can disable MD5-based NetLogon by adding the following snippet to their smb.conf ~~~ reject md5 clients = yes ~~~ in case there's still need to allow SMB to authenticate to MD5-based NetLogon servers, it's possible to explicitly enable it per-server based: ~~~ server reject md5โ€ฆ

Description

samba: RC4/HMAC-MD5 NetLogon Secure Channel is weak and should be avoided

Red Hat statement

Users can disable MD5-based NetLogon by adding the following snippet to their smb.conf ~~~ reject md5 clients = yes ~~~ in case there's still need to allow SMB to authenticate to MD5-based NetLogon servers, it's possible to explicitly enable it per-server based: ~~~ server reject md5 schannel:<SERVERNAME>$ = no ~~~

CVSS v3: 8.1 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)

Errata / fixed releases

ProductPackageAdvisoryReleased
Red Hat Enterprise Linux 7samba-0:4.10.16-24.el7_9RHSA-2023:10902023-03-07T00:00:00Z
Red Hat Enterprise Linux 8samba-0:4.16.4-4.el8_7RHSA-2023:08382023-02-21T00:00:00Z
Red Hat Enterprise Linux 8samba-0:4.16.4-4.el8_7RHSA-2023:08382023-02-21T00:00:00Z
Red Hat Enterprise Linux 8.1 Update Services for SAP Solutionssamba-0:4.10.4-107.el8_1RHSA-2023:06392023-02-07T00:00:00Z
Red Hat Enterprise Linux 8.2 Advanced Update Supportsamba-0:4.11.2-22.el8_2RHSA-2023:06382023-02-07T00:00:00Z
Red Hat Enterprise Linux 8.2 Telecommunications Update Servicesamba-0:4.11.2-22.el8_2RHSA-2023:06382023-02-07T00:00:00Z
Red Hat Enterprise Linux 8.2 Update Services for SAP Solutionssamba-0:4.11.2-22.el8_2RHSA-2023:06382023-02-07T00:00:00Z
Red Hat Enterprise Linux 8.4 Extended Update Supportsamba-0:4.13.3-11.el8_4RHSA-2023:06372023-02-07T00:00:00Z
Red Hat Enterprise Linux 8.6 Extended Update Supportsamba-0:4.15.5-12.el8_6RHSA-2023:21362023-05-04T00:00:00Z
Red Hat Enterprise Linux 9samba-0:4.16.4-103.el9_1RHSA-2023:21272023-05-04T00:00:00Z
Red Hat Enterprise Linux 9samba-0:4.16.4-103.el9_1RHSA-2023:21272023-05-04T00:00:00Z
Red Hat Enterprise Linux 9.0 Extended Update Supportsamba-0:4.15.5-110.el9_0RHSA-2023:21372023-05-04T00:00:00Z
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8samba-0:4.15.5-12.el8_6RHSA-2023:21362023-05-04T00:00:00Z
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8redhat-virtualization-host-0:4.5.3-202306050942_8.6RHSA-2023:34912023-06-06T00:00:00Z

Package state

ProductPackageState
Red Hat Enterprise Linux 6sambaOut of support scope
Red Hat Storage 3sambaNot affected

Apply commands

bash fix
Apply RHSA-2023:1090 for Red Hat Enterprise Linux 7
yum update -y samba
# or:
dnf upgrade -y samba

Affected

VendorProductVersion
redhatRed Hat Storage 3Not affected

OS impact

OSVersionStatusFixed in
arch archfixed4.17.5-1
redhat rhel9fixed
rockylinux rocky8fixed
suse slesaffected
rockylinux rocky9fixed
debian debianbookwormfixed2:4.17.4+dfsg-1
debian debianbullseyeaffected
debian debianforkyfixed2:4.17.4+dfsg-1
debian debiansidfixed2:4.17.4+dfsg-1
debian debiantrixiefixed2:4.17.4+dfsg-1
almalinux almalinux9fixedsamba-vfs-iouring-4.16.4-103.el9_1.aarch64.rpm
almalinux almalinux8fixedsamba-common-4.16.4-4.el8_7.noarch.rpm

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.