Kwetsbaarheid in Samba waardoor remote code-executie op de server mogelijk is

Corrective releases of Samba package 4.23.2, 4.22.5, and 4.21.9 have been published, addressing a vulnerability (CVE-2025-10230) in the implementation of the WINS name resolution server that allows remote code execution on the server without authentication. This issue has been assigned a maximum severity level — 10 out of 10.

The vulnerability is caused by insufficient validation of values passed before executing the application specified in the 'wins hook' parameter. This application is run via the 'sh -c' command whenever a name is changed using WINS. When using WINS on the Active Directory controller, NetBIOS names passed as command-line arguments during the hook application launch were not sanitized for special characters, allowing arbitrary shell commands to be executed by specifying a specially crafted NetBIOS name in a request to the WINS server. domein Active Directory, NetBIOS-namen die als argumenten in de opdrachtregel worden doorgegeven bij het starten van de hook-applicatie, werden niet ontdaan van speciale tekens, waardoor het mogelijk was om willekeurige shell-commando's uit te voeren door een speciaal geformatteerde NetBIOS-naam in het verzoek aan de WINS-server op te geven. cmd = talloc_asprintf(tmp_mem, "%s %s %s x %ld", wins_hook_script, wins_hook_action_string(action), rec->name->name, rec->name->type, (long int) rec->expire_time); … execl("/bin/sh", "sh", "-c", cmd, NULL);

An unauthenticated client can send a registration packet to the WINS server and request any NetBIOS name not exceeding 15 characters. Characters such as '', and ';' are not sanitized in the name. Consequently, when the hook handler is executed, passing a name like 'name;id>file' will lead to the execution of the 'id' utility and direct output to the file 'file'.

The vulnerability is present on systems where the 'wins hook' parameter is set in smb.conf when using a domain controller with WINS (which is disabled by default and requires enabling the parameter 'wins support = yes'). When using a WINS server in systems without a domain controller, the vulnerability does not manifest. server You can check the status of the new package version or fix preparation in distributions on the following pages: Debian, Ubuntu, Fedora, SUSE/openSUSE, RHEL, Gentoo, Arch, FreeBSD, OpenBSD, and NetBSD.

In de gepubliceerde versies van Samba is ook een minder ernstige kwetsbaarheid verholpen (CVE-2025-9640), die leidt tot het lekken van niet-geïnitieerde geheugen. Het probleem doet zich voor in de module vfs_streams_xattr bij geheugenallocatiefouten, die kunnen worden veroorzaakt door schrijfoperaties die lege gebieden in een bestand creëren. De kwetsbaarheid kan worden misbruikt door een geauthenticeerde gebruiker.

Bron: opennet.ru

Koop betrouwbare webhosting met bescherming tegen DDoS, VPS VDS servers šŸ”„ Koop betrouwbare webhosting met bescherming tegen DDoS, VPS VDS servers | ProHoster