Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-7489.json
JSON Data
https://api.test.osv.dev/v1/vulns/AZL-7489
Upstream
Published
2022-01-11T16:15:07Z
Modified
2026-04-01T05:22:47.016960Z
Severity
  • 2.5 (Low) CVSS_V3 - CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N CVSS Calculator
Summary
CVE-2021-43566 affecting package samba 4.12.5-7
Details

All versions of Samba prior to 4.13.16 are vulnerable to a malicious client using an SMB1 or NFS race to allow a directory to be created in an area of the server file system not exported under the share definition. Note that SMB1 has to be enabled, or the share also available via NFS in order for this attack to succeed.

References

Affected packages

Azure Linux:2 / samba

Package

Name
samba
Purl
pkg:rpm/azure-linux/samba

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
4.12.5-7

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-7489.json"