A null pointer de-reference was found in the way samba kerberos server handled missing sname in TGS-REQ (Ticket Granting Server - Request). An authenticated user could use this flaw to crash the samba server.
{
"unresolved_ranges": [
{
"cpe": "cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*",
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "10.0"
}
]
},
{
"cpe": "cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*",
"extracted_events": [
{
"last_affected": "11.0"
}
],
"source": "CPE_FIELD"
}
]
}"2026-04-12T00:39:58Z"
[
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"71814477620078668530731684481303091670",
"284346098059572621942400253662874014995",
"63355110677909982606625851675836965070",
"200771017170665811656047669952130469804"
]
},
"signature_type": "Line",
"id": "CVE-2021-3671-5f6e87fc",
"signature_version": "v1",
"source": "https://github.com/heimdal/heimdal/commit/04171147948d0a3636bc6374181926f0fb2ec83a",
"target": {
"file": "kdc/krb5tgs.c"
},
"deprecated": false
},
{
"digest": {
"length": 21025.0,
"function_hash": "332444689167320886733846614105216309617"
},
"signature_type": "Function",
"deprecated": false,
"id": "CVE-2021-3671-e212c18a",
"source": "https://github.com/heimdal/heimdal/commit/04171147948d0a3636bc6374181926f0fb2ec83a",
"target": {
"function": "tgs_build_reply",
"file": "kdc/krb5tgs.c"
},
"signature_version": "v1"
}
]
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-3671.json"
{
"cpe": "cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "4.13.12"
},
{
"introduced": "4.14.0"
},
{
"fixed": "4.14.8"
}
],
"source": "CPE_FIELD"
}