Critical severity9.8NVD Advisory· Published Nov 27, 2017· Updated Jun 17, 2026
CVE-2017-14746
CVE-2017-14746
Description
Use-after-free vulnerability in Samba 4.x before 4.7.3 allows remote attackers to execute arbitrary code via a crafted SMB1 request.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
33cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*range: >=4.0.0,<4.5.0
- (no CPE)range: <4.7.3
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*+ 3 more
- cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:17.04:*:*:*:*:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:17.10:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*
- osv-coords19 versionspkg:rpm/opensuse/samba&distro=openSUSE%20Tumbleweedpkg:rpm/suse/samba&distro=SUSE%20Enterprise%20Storage%205pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP2pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP3pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2012pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2012%20SP1pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2012%20SP2pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2012%20SP3pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP1-LTSSpkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Server%2012-LTSSpkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Server%20for%20Raspberry%20Pi%2012%20SP2pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP1pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP2pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP3pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP2pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP3pkg:rpm/suse/samba&distro=SUSE%20OpenStack%20Cloud%206
< 4.14.6+git.182.2205d5224e3-1.1+ 18 more
- (no CPE)range: < 4.14.6+git.182.2205d5224e3-1.1
- (no CPE)range: < 4.6.9+git.59.c2cff9cea4c-3.17.1
- (no CPE)range: < 4.2.4-28.24.1
- (no CPE)range: < 4.6.9+git.59.c2cff9cea4c-3.17.1
- (no CPE)range: < 4.2.4-18.49.1
- (no CPE)range: < 4.2.4-28.24.1
- (no CPE)range: < 4.4.2-38.14.1
- (no CPE)range: < 4.6.9+git.59.c2cff9cea4c-3.17.1
- (no CPE)range: < 4.2.4-28.24.1
- (no CPE)range: < 4.2.4-28.24.1
- (no CPE)range: < 4.6.9+git.59.c2cff9cea4c-3.17.1
- (no CPE)range: < 4.2.4-18.49.1
- (no CPE)range: < 4.2.4-28.24.1
- (no CPE)range: < 4.2.4-28.24.1
- (no CPE)range: < 4.2.4-28.24.1
- (no CPE)range: < 4.6.9+git.59.c2cff9cea4c-3.17.1
- (no CPE)range: < 4.2.4-28.24.1
- (no CPE)range: < 4.6.9+git.59.c2cff9cea4c-3.17.1
- (no CPE)range: < 4.2.4-28.24.1
Patches
Vulnerability mechanics
References
11- www.securityfocus.com/bid/101907nvdThird Party AdvisoryVDB Entry
- www.securitytracker.com/id/1039856nvdThird Party AdvisoryVDB Entry
- www.ubuntu.com/usn/USN-3486-1nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2017:3260nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2017:3261nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2017:3278nvdThird Party Advisory
- security.gentoo.org/glsa/201805-07nvdThird Party Advisory
- support.hpe.com/hpsc/doc/public/displaynvdThird Party Advisory
- www.debian.org/security/2017/dsa-4043nvdThird Party Advisory
- www.samba.org/samba/security/CVE-2017-14746.htmlnvdIssue TrackingVendor Advisory
- www.synology.com/support/security/Synology_SA_17_72_SambanvdThird Party Advisory
News mentions
0No linked articles in our index yet.