CVE-2021-20316

A flaw was found in the way Samba handled file/directory metadata. This flaw allows an authenticated attacker with permissions to read or modify share metadata, to perform this operation outside of the share.
Race Condition
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.8 MEDIUM
NETWORK
HIGH
LOW
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 60%
VendorProductVersion
sambasamba
𝑥
< 4.15.0
debiandebian_linux
10.0
debiandebian_linux
11.0
redhatvirtualization_host
4.0
redhatenterprise_linux
8.0
redhatenterprise_linux_aus
8.6
redhatenterprise_linux_eus
8.6
redhatenterprise_linux_tus
8.6
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
samba
bullseye (security)
vulnerable
bullseye
ignored
buster
ignored
bookworm
2:4.17.12+dfsg-0+deb12u1
fixed
bookworm (security)
2:4.17.12+dfsg-0+deb12u1
fixed
sid
2:4.21.1+dfsg-2
fixed
trixie
2:4.21.1+dfsg-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
samba
noble
not-affected
mantic
not-affected
lunar
not-affected
kinetic
ignored
jammy
ignored
impish
ignored
hirsute
ignored
focal
ignored
bionic
ignored
xenial
needed
trusty
needed