CVE-2021-44142
HIGH EXPLOITEDRedhat Enterprise Linux For Scientific Computing - Out-of-Bounds Write
Title source: ruleDescription
The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "...enhanced compatibility with Apple SMB clients and interoperability with a Netatalk 3 AFP fileserver." Samba versions prior to 4.13.17, 4.14.12 and 4.15.5 with vfs_fruit configured allow out-of-bounds heap read and write via specially crafted extended file attributes. A remote attacker with write access to extended file attributes can execute arbitrary code with the privileges of smbd, typically root.
Exploits (5)
nomisec
WORKING POC
3 stars
by Nxvh1337 · poc
https://github.com/Nxvh1337/CVE-2021-44142-vulnerable-lab
nomisec
WORKING POC
3 stars
by WinDyAlphA · poc
https://github.com/WinDyAlphA/CVE-2021-44142-vulnerable-lab
References (6)
Scores
CVSS v3
8.8
EPSS
0.3740
EPSS Percentile
97.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
VulnCheck KEV
2024-07-25
CWE
CWE-125
CWE-787
Status
published
Products (40)
canonical/ubuntu_linux
14.04
canonical/ubuntu_linux
16.04
canonical/ubuntu_linux
18.04
canonical/ubuntu_linux
20.04
canonical/ubuntu_linux
21.10
debian/debian_linux
10.0
debian/debian_linux
11.0
fedoraproject/fedora
34
fedoraproject/fedora
35
redhat/codeready_linux_builder
... and 30 more
Published
Feb 21, 2022
Tracked Since
Feb 18, 2026