Medium severity6.5NVD Advisory· Published Oct 12, 2021· Updated Jun 17, 2026
CVE-2021-3671
CVE-2021-3671
Description
A null pointer de-reference was found in the way samba kerberos server handled missing sname in TGS-REQ (Ticket Granting Server - Request). An authenticated user could use this flaw to crash the samba server.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
13- cpe:2.3:a:netapp:management_services_for_element_software:-:*:*:*:*:*:*:*
- cpe:2.3:a:netapp:management_services_for_netapp_hci:-:*:*:*:*:*:*:*
- cpe:2.3:a:netapp:ontap_select_deploy_administration_utility:-:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*range: <4.13.12
- (no CPE)
- samba/sambadescription
- osv-coords4 versionspkg:rpm/opensuse/libheimdal&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/libheimdal&distro=openSUSE%20Leap%2015.4pkg:rpm/suse/libheimdal&distro=SUSE%20Package%20Hub%2015%20SP3pkg:rpm/suse/libheimdal&distro=SUSE%20Package%20Hub%2015%20SP4
< 7.8.0-bp153.2.4.1+ 3 more
- (no CPE)range: < 7.8.0-bp153.2.4.1
- (no CPE)range: < 7.8.0-bp154.2.4.1
- (no CPE)range: < 7.8.0-bp153.2.4.1
- (no CPE)range: < 7.8.0-bp154.2.4.1
Patches
Vulnerability mechanics
References
7- github.com/heimdal/heimdal/commit/04171147948d0a3636bc6374181926f0fb2ec83anvdPatchThird Party Advisory
- lists.debian.org/debian-lts-announce/2022/11/msg00034.htmlnvdMailing ListThird Party Advisory
- security.netapp.com/advisory/ntap-20221215-0002/nvdThird Party Advisory
- security.netapp.com/advisory/ntap-20230216-0008/nvdThird Party Advisory
- www.debian.org/security/2022/dsa-5287nvdThird Party Advisory
- bugzilla.redhat.com/show_bug.cginvd
- bugzilla.samba.org/show_bug.cginvd
News mentions
0No linked articles in our index yet.