Unrated severityNVD Advisory· Published Aug 25, 2022· Updated Aug 3, 2024
CVE-2022-32742
CVE-2022-32742
Description
A flaw was found in Samba. Some SMB1 write requests were not correctly range-checked to ensure the client had sent enough data to fulfill the write, allowing server memory contents to be written into the file (or printer) instead of client-supplied data. The client cannot control the area of the server memory written to the file (or printer).
Affected products
80- Samba/Sambadescription
- osv-coords79 versionspkg:rpm/almalinux/ctdbpkg:rpm/almalinux/libsmbclientpkg:rpm/almalinux/libsmbclient-develpkg:rpm/almalinux/libwbclientpkg:rpm/almalinux/libwbclient-develpkg:rpm/almalinux/python3-sambapkg:rpm/almalinux/python3-samba-testpkg:rpm/almalinux/sambapkg:rpm/almalinux/samba-clientpkg:rpm/almalinux/samba-client-libspkg:rpm/almalinux/samba-commonpkg:rpm/almalinux/samba-common-libspkg:rpm/almalinux/samba-common-toolspkg:rpm/almalinux/samba-develpkg:rpm/almalinux/samba-krb5-printingpkg:rpm/almalinux/samba-libspkg:rpm/almalinux/samba-pidlpkg:rpm/almalinux/samba-testpkg:rpm/almalinux/samba-test-libspkg:rpm/almalinux/samba-vfs-iouringpkg:rpm/almalinux/samba-winbindpkg:rpm/almalinux/samba-winbind-clientspkg:rpm/almalinux/samba-winbind-krb5-locatorpkg:rpm/almalinux/samba-winbind-modulespkg:rpm/almalinux/samba-winexepkg:rpm/opensuse/ldb&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/ldb&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/ldb&distro=openSUSE%20Leap%20Micro%205.2pkg:rpm/opensuse/samba&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/samba&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/samba&distro=openSUSE%20Leap%20Micro%205.2pkg:rpm/opensuse/samba&distro=openSUSE%20Leap%20Micro%205.3pkg:rpm/opensuse/samba&distro=openSUSE%20Tumbleweedpkg:rpm/suse/ldb&distro=SUSE%20Enterprise%20Storage%207.1pkg:rpm/suse/ldb&distro=SUSE%20Linux%20Enterprise%20Micro%205.1pkg:rpm/suse/ldb&distro=SUSE%20Linux%20Enterprise%20Micro%205.2pkg:rpm/suse/ldb&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP3pkg:rpm/suse/ldb&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP4pkg:rpm/suse/samba&distro=SUSE%20Enterprise%20Storage%206pkg:rpm/suse/samba&distro=SUSE%20Enterprise%20Storage%207pkg:rpm/suse/samba&distro=SUSE%20Enterprise%20Storage%207.1pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2012%20SP4pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2012%20SP5pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2015pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2015%20SP1pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2015%20SP2pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2015%20SP3pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2015%20SP4pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-ESPOSpkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-LTSSpkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-ESPOSpkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-LTSSpkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-ESPOSpkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-LTSSpkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Micro%205.2pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Micro%205.3pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP3pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP4pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Python%202%2015%20SP3pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-BCLpkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3-BCLpkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4-LTSSpkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-BCLpkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-LTSSpkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP2-BCLpkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP2-LTSSpkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Server%2015-LTSSpkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP1pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP2pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5pkg:rpm/suse/samba&distro=SUSE%20Manager%20Proxy%204.1pkg:rpm/suse/samba&distro=SUSE%20Manager%20Retail%20Branch%20Server%204.1pkg:rpm/suse/samba&distro=SUSE%20Manager%20Server%204.1pkg:rpm/suse/samba&distro=SUSE%20OpenStack%20Cloud%209pkg:rpm/suse/samba&distro=SUSE%20OpenStack%20Cloud%20Crowbar%209
< 4.15.5-10.el8_6+ 78 more
- (no CPE)range: < 4.15.5-10.el8_6
- (no CPE)range: < 4.15.5-10.el8_6
- (no CPE)range: < 4.15.5-10.el8_6
- (no CPE)range: < 4.15.5-10.el8_6
- (no CPE)range: < 4.15.5-10.el8_6
- (no CPE)range: < 4.15.5-10.el8_6
- (no CPE)range: < 4.15.5-10.el8_6
- (no CPE)range: < 4.15.5-10.el8_6
- (no CPE)range: < 4.15.5-10.el8_6
- (no CPE)range: < 4.15.5-10.el8_6
- (no CPE)range: < 4.15.5-10.el8_6
- (no CPE)range: < 4.15.5-10.el8_6
- (no CPE)range: < 4.15.5-10.el8_6
- (no CPE)range: < 4.15.5-10.el8_6
- (no CPE)range: < 4.15.5-10.el8_6
- (no CPE)range: < 4.15.5-10.el8_6
- (no CPE)range: < 4.15.5-10.el8_6
- (no CPE)range: < 4.15.5-10.el8_6
- (no CPE)range: < 4.15.5-10.el8_6
- (no CPE)range: < 4.15.5-10.el8_6
- (no CPE)range: < 4.15.5-10.el8_6
- (no CPE)range: < 4.15.5-10.el8_6
- (no CPE)range: < 4.15.5-10.el8_6
- (no CPE)range: < 4.15.5-10.el8_6
- (no CPE)range: < 4.15.5-10.el8_6
- (no CPE)range: < 2.4.3-150300.3.20.1
- (no CPE)range: < 2.4.3-150400.4.8.1
- (no CPE)range: < 2.4.3-150300.3.20.1
- (no CPE)range: < 4.15.8+git.500.d5910280cc7-150300.3.37.1
- (no CPE)range: < 4.9.5+git.490.e80cf669f50-150100.3.70.1
- (no CPE)range: < 4.15.8+git.500.d5910280cc7-150300.3.37.1
- (no CPE)range: < 4.15.13+git.591.ab36624310c-150400.3.19.1
- (no CPE)range: < 4.16.4+git.297.1497eb221ed-1.1
- (no CPE)range: < 2.4.3-150300.3.20.1
- (no CPE)range: < 2.4.3-150300.3.20.1
- (no CPE)range: < 2.4.3-150300.3.20.1
- (no CPE)range: < 2.4.3-150300.3.20.1
- (no CPE)range: < 2.4.3-150400.4.8.1
- (no CPE)range: < 4.9.5+git.490.e80cf669f50-150100.3.70.1
- (no CPE)range: < 4.11.14+git.325.2e31b7efa01-150200.4.41.1
- (no CPE)range: < 4.15.8+git.500.d5910280cc7-150300.3.37.1
- (no CPE)range: < 4.6.16+git.324.6bba9ddab76-3.73.1
- (no CPE)range: < 4.15.8+git.462.e73f4310487-3.68.1
- (no CPE)range: < 4.7.11+git.369.b2cad0ee592-150000.4.66.1
- (no CPE)range: < 4.9.5+git.490.e80cf669f50-150100.3.70.1
- (no CPE)range: < 4.11.14+git.325.2e31b7efa01-150200.4.41.1
- (no CPE)range: < 4.15.8+git.500.d5910280cc7-150300.3.37.1
- (no CPE)range: < 4.15.8+git.500.d5910280cc7-150400.3.11.1
- (no CPE)range: < 4.9.5+git.490.e80cf669f50-150100.3.70.1
- (no CPE)range: < 4.9.5+git.490.e80cf669f50-150100.3.70.1
- (no CPE)range: < 4.11.14+git.325.2e31b7efa01-150200.4.41.1
- (no CPE)range: < 4.11.14+git.325.2e31b7efa01-150200.4.41.1
- (no CPE)range: < 4.7.11+git.369.b2cad0ee592-150000.4.66.1
- (no CPE)range: < 4.7.11+git.369.b2cad0ee592-150000.4.66.1
- (no CPE)range: < 4.15.8+git.500.d5910280cc7-150300.3.37.1
- (no CPE)range: < 4.15.13+git.591.ab36624310c-150400.3.19.1
- (no CPE)range: < 4.15.8+git.500.d5910280cc7-150300.3.37.1
- (no CPE)range: < 4.15.8+git.500.d5910280cc7-150400.3.11.1
- (no CPE)range: < 4.15.8+git.500.d5910280cc7-150300.3.37.1
- (no CPE)range: < 4.4.2-38.55.1
- (no CPE)range: < 4.6.16+git.324.6bba9ddab76-3.73.1
- (no CPE)range: < 4.6.16+git.324.6bba9ddab76-3.73.1
- (no CPE)range: < 4.15.8+git.462.e73f4310487-3.68.1
- (no CPE)range: < 4.9.5+git.490.e80cf669f50-150100.3.70.1
- (no CPE)range: < 4.9.5+git.490.e80cf669f50-150100.3.70.1
- (no CPE)range: < 4.11.14+git.325.2e31b7efa01-150200.4.41.1
- (no CPE)range: < 4.11.14+git.325.2e31b7efa01-150200.4.41.1
- (no CPE)range: < 4.7.11+git.369.b2cad0ee592-150000.4.66.1
- (no CPE)range: < 4.6.16+git.324.6bba9ddab76-3.73.1
- (no CPE)range: < 4.15.8+git.462.e73f4310487-3.68.1
- (no CPE)range: < 4.7.11+git.369.b2cad0ee592-150000.4.66.1
- (no CPE)range: < 4.9.5+git.490.e80cf669f50-150100.3.70.1
- (no CPE)range: < 4.11.14+git.325.2e31b7efa01-150200.4.41.1
- (no CPE)range: < 4.15.8+git.462.e73f4310487-3.68.1
- (no CPE)range: < 4.11.14+git.325.2e31b7efa01-150200.4.41.1
- (no CPE)range: < 4.11.14+git.325.2e31b7efa01-150200.4.41.1
- (no CPE)range: < 4.11.14+git.325.2e31b7efa01-150200.4.41.1
- (no CPE)range: < 4.6.16+git.324.6bba9ddab76-3.73.1
- (no CPE)range: < 4.6.16+git.324.6bba9ddab76-3.73.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- security.gentoo.org/glsa/202309-06mitrevendor-advisory
- lists.debian.org/debian-lts-announce/2024/04/msg00015.htmlmitremailing-list
- www.samba.org/samba/security/CVE-2022-32742.htmlmitre
News mentions
0No linked articles in our index yet.