CVE-2019-19344

MEDIUM

Samba <4.9.18-4.11.5 - Use After Free

Title source: llm
STIX 2.1

Description

There is a use-after-free issue in all samba 4.9.x versions before 4.9.18, all samba 4.10.x versions before 4.10.12 and all samba 4.11.x versions before 4.11.5, essentially due to a call to realloc() while other local variables still point at the original buffer.

Scores

CVSS v3 6.5
EPSS 0.0219
EPSS Percentile 84.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-416
Status published
Products (10)
canonical/ubuntu_linux 16.04
canonical/ubuntu_linux 18.04
canonical/ubuntu_linux 19.04
canonical/ubuntu_linux 19.10
opensuse/leap 15.1
samba/samba 4.9.0 - 4.9.18
synology/directory_server
synology/diskstation_manager 6.2
synology/router_manager 1.2
synology/skynas
Published Jan 21, 2020
Tracked Since Feb 18, 2026