SUSE Support

Here When You Need Us

Security vulnerability: Samba directory traversal CVE-2021-43566

This document (000020571) is provided subject to the disclaimer at the end of this document.

Environment

For a comprehensive list of affected products and package versions, please visit the SUSE CVE announcement:
https://www.suse.com/security/cve/CVE-2021-43566.html

Situation

Directory traversal vulnerabilities in Samba were identified when using SMB1 or with the share also exported via NFS, might allow remote attackers to create directories on the file server outside of the exported shared area.

Resolution

SUSE will provide fixes samba 4.15.4 updates for SUSE Linux Enterprise 12 SP5 and 15 SP3 and later versions, but  currently does not plan this for older Service Packs due to complexity of the backport.

For older service packs please apply the mitigations.

Status

Security Alert

Additional Information

Workaround:

A mitigation is to disable SMB1 (already default disabled in Samba 4.11 and newer), or if SMB1 is required for compatibility reasons disable the UNIX extensions by setting:

unix extensions = no

in the [global] section of /etc/samba/smb.conf and restarting Samba
after the change.

Disclaimer

This Support Knowledgebase provides a valuable tool for SUSE customers and parties interested in our products and solutions to acquire information, ideas and learn from one another. Materials are provided for informational, personal or non-commercial use within your organization and are presented "AS IS" WITHOUT WARRANTY OF ANY KIND.

  • Document ID:000020571
  • Creation Date: 31-Jan-2022
  • Modified Date:31-Jan-2022

< Back to Support Search

For questions or concerns with the SUSE Knowledgebase please contact: tidfeedback[at]suse.com

SUSE Support Forums

Get your questions answered by experienced Sys Ops or interact with other SUSE community experts.

Support Resources

Learn how to get the most from the technical support you receive with your SUSE Subscription, Premium Support, Academic Program, or Partner Program.

Open an Incident

Open an incident with SUSE Technical Support, manage your subscriptions, download patches, or manage user access.