CVE-2022-2127 - CVE House
Back to Database
Status published Medium CVE-2022-2127

Samba: out-of-bounds read in winbind auth_crap

Vulnerability Description

An out-of-bounds read vulnerability was found in Samba due to insufficient length checks in winbindd_pam_auth_crap.c. When performing NTLM authentication, the client replies to cryptographic challenges back to the server. These replies have variable lengths, and Winbind fails to check the lan manager response length. When Winbind is used for NTLM authentication, a maliciously crafted request can trigger an out-of-bounds read in Winbind, possibly resulting in a crash.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-2127

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 8.6 Extended Update Support, Red Hat Enterprise Linux 8.8 Extended Update Support, Red Hat Enterprise Linux 9, Red Hat Virtualization 4 for Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Storage 3
Vulnerable Versions:
0:4.18.6-1.el8, 0:4.15.5-15.el8_6, 0:4.17.5-5.el8_8, 0:4.18.6-100.el9

Timeline

Official Publish: July 20th, 2023
Last Modified: November 20th, 2025
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Weaknesses (CWE)