CVE-2022-37966 @ Bullseye
Package interrogation (copy)
Run on the host — click to copy a command. Debian/apt
| Package | Commands |
|---|---|
| samba-4.13.13+dfsg-1~deb11u8 | |
| samba-common-4.13.13+dfsg-1~deb11u8 | |
| samba-common-bin-4.13.13+dfsg-1~deb11u8 | |
| samba-dsdb-modules-4.13.13+dfsg-1~deb11u8 | |
| samba-libs-4.13.13+dfsg-1~deb11u8 | |
| samba-vfs-modules |
Inventory lookup
Search package inventory across systems, then return here. Create a ticket on systems the matcher missed.
Suggestions: samba · samba-common · samba-common-bin · samba-dsdb-modules · samba-libs · samba-vfs-modules
| System | Matches | Ticket for CVE-2022-37966 | |
|---|---|---|---|
| Archive | samba-common 2:4.9.5+dfsg-5+deb10u5; samba-common-bin 2:4.9.5+dfsg-5+deb10u5 | accepted_risk open | |
| Bullseye | samba-common 2:4.13.13+dfsg-1~deb11u8; samba-common-bin 2:4.13.13+dfsg-1~deb11u8 | accepted_risk open | |
| Library | samba-common 2:4.5.16+dfsg-1+deb9u4; samba-common-bin 2:4.5.16+dfsg-1+deb9u4 | accepted_risk open | |
| Saiph | samba-common 2:4.9.5+dfsg-5+deb10u5; samba-common-bin 2:4.9.5+dfsg-5+deb10u5 | accepted_risk open | |
| Matrix | samba-common 2:4.17.12+dfsg-0+deb12u4; samba-common-bin 2:4.17.12+dfsg-0+deb12u4 | none |
Same product CVEs in your queue
Other tickets that look like the same product (from match reason). Relate them here to triage this CVE as the primary.
| CVE | CVSS | KEV | Systems | Status | Matched | Already related | |
|---|---|---|---|---|---|---|---|
| CVE-2026-4408 | 9.0 | Archive, Library, Saiph | new | samba-common-bin | — | ||
| CVE-2022-38023 | 8.1 | Archive, Bullseye, Library, Saiph | accepted_risk | samba-common-bin | — | ||
| CVE-2026-3644 | 7.5 | Library | accepted_risk | samba | — | ||
| CVE-2026-4224 | 7.5 | Library | accepted_risk | samba | — | ||
| CVE-2026-7210 | 7.5 | Library | accepted_risk | samba | → CVE-2026-15308 | ||
| CVE-2026-15308 | 7.5 | Library | accepted_risk | samba | — | ||
| CVE-2022-37967 | 7.2 | Archive, Bullseye, Library, Saiph | not_applicable | samba-common-bin | → CVE-2022-37966 | linked here |
Related CVE (same fix)
Point this ticket’s CVE at a higher-priority / same-fix primary so you only triage one.
Other CVEs related to this one as primary:
| Related CVE | Note | Tickets |
|---|---|---|
| CVE-2022-37967 | same product as CVE-2022-37966 | Library, Archive, Bullseye, Saiph |
Host OS / kernel
uname -r → 5.10.0-45-amd64uname -v → #1 SMP Debian 5.10.259-1 (2026-07-02)For Linux kernel CVEs, kernel_version (Debian packaging / build string) often decides fixed vs not; kernel_release is used for upstream NVD range compares.
Same CVE on other hosts
Open the ticket for this CVE on another system.
| System | Status | Priority | Updated | |
|---|---|---|---|---|
| Library | accepted_risk | 4.43 | 2026-08-22T10:16:15Z | Open |
| Archive | accepted_risk | 3.21 | 2026-08-22T10:16:15Z | Open |
| Saiph | accepted_risk | 3.21 | 2026-08-22T10:16:15Z | Open |
Description
Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability
Determination
ulnerability: Weak RC4-HMAC Kerberos session keys issued by Samba AD Domain Controllers Impact: Elevation of privilege (Kerberos ticket attacks) Affected: All Samba versions that act as an AD DC (or use Kerberos with RC4) Fixed upstream: 4.15.13 / 4.16.8 / 4.17.4 If this Samba instance is only used as a simple file server (no AD DC role), the practical risk is significantly lower, but the code is still vulnerable. No public access
Update status
Add note only
Mitigation log
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-37966
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-37966
- https://security.gentoo.org/glsa/202309-06
NVD: CVE-2022-37966