CVE Tracker

CVE-2022-37966 @ Saiph

Status
accepted_risk
Priority
3.21
Match score
4.0
Risk
PrivEsc MemCorrupt Remote priv:admin
CVSS
8.1 HIGH
Reason
cpe: samba; pkgs: samba, samba-common, samba-common-bin, samba-dsdb-modules, samba-libs, samba-vfs-modules; version: in-range: samba-4.9.5+dfsg-5+deb10u5, samba-4.9.5+dfsg-5+deb10u5, samba-common-4.9.5+dfsg-5+deb10u5, samba-common-bin-4.9.5+dfsg-5+deb10u5, samba-dsdb-modules-4.9.5+dfsg-5+deb10u5, samba-libs-4.9.5+dfsg-5+deb10u5; risk:priv_esc; remote
Created
2026-08-11T10:15:46Z
Updated
2026-08-22T10:16:15Z
Closed
2026-08-11T15:31:52Z

Package interrogation (copy)

Run on the host — click to copy a command. Debian/apt

PackageCommands
samba-4.9.5+dfsg-5+deb10u5
samba-common-4.9.5+dfsg-5+deb10u5
samba-common-bin-4.9.5+dfsg-5+deb10u5
samba-dsdb-modules-4.9.5+dfsg-5+deb10u5
samba-libs-4.9.5+dfsg-5+deb10u5
samba-vfs-modules

Inventory lookup

Search package inventory across systems, then return here. Create a ticket on systems the matcher missed.

Clear

Suggestions: samba · samba-common · samba-common-bin · samba-dsdb-modules · samba-libs · samba-vfs-modules

SystemMatchesTicket for CVE-2022-37966
Archive python-samba 2:4.9.5+dfsg-5+deb10u5; samba 2:4.9.5+dfsg-5+deb10u5; samba-common 2:4.9.5+dfsg-5+deb10u5; samba-common-bin 2:4.9.5+dfsg-5+deb10u5; samba-dsdb-modules 2:4.9.5+dfsg-5+deb10u5; samba-libs 2:4.9.5+dfsg-5+deb10u5; samba-vfs-modules 2:4.9.5+dfsg-5+deb10u5 accepted_risk open
Bullseye python3-samba 2:4.13.13+dfsg-1~deb11u8; samba 2:4.13.13+dfsg-1~deb11u8; samba-common 2:4.13.13+dfsg-1~deb11u8; samba-common-bin 2:4.13.13+dfsg-1~deb11u8; samba-dsdb-modules 2:4.13.13+dfsg-1~deb11u8; samba-libs 2:4.13.13+dfsg-1~deb11u8; samba-vfs-modules 2:4.13.13+dfsg-1~deb11u8 accepted_risk open
Library python-samba 2:4.5.16+dfsg-1+deb9u4; samba 2:4.5.16+dfsg-1+deb9u4; samba-common 2:4.5.16+dfsg-1+deb9u4; samba-common-bin 2:4.5.16+dfsg-1+deb9u4; samba-dsdb-modules 2:4.5.16+dfsg-1+deb9u4; samba-libs 2:4.5.16+dfsg-1+deb9u4; samba-vfs-modules 2:4.5.16+dfsg-1+deb9u4 accepted_risk open
Saiph python-samba 2:4.9.5+dfsg-5+deb10u5; samba 2:4.9.5+dfsg-5+deb10u5; samba-common 2:4.9.5+dfsg-5+deb10u5; samba-common-bin 2:4.9.5+dfsg-5+deb10u5; samba-dsdb-modules 2:4.9.5+dfsg-5+deb10u5; samba-libs 2:4.9.5+dfsg-5+deb10u5; samba-vfs-modules 2:4.9.5+dfsg-5+deb10u5 accepted_risk open
Matrix python3-samba 2:4.17.12+dfsg-0+deb12u4; samba-common 2:4.17.12+dfsg-0+deb12u4; samba-common-bin 2:4.17.12+dfsg-0+deb12u4; samba-dsdb-modules 2:4.17.12+dfsg-0+deb12u4; samba-libs 2:4.17.12+dfsg-0+deb12u4 none

Same product CVEs in your queue

Other tickets that look like the same product (from match reason). Relate them here to triage this CVE as the primary.

CVECVSSKEVSystemsStatus MatchedAlready related
CVE-2026-4408 9.0 Archive, Library, Saiph new samba-common-bin
CVE-2022-38023 8.1 Archive, Bullseye, Library, Saiph accepted_risk samba-common-bin
CVE-2026-3644 7.5 Library accepted_risk samba
CVE-2026-4224 7.5 Library accepted_risk samba
CVE-2026-7210 7.5 Library accepted_risk samba → CVE-2026-15308
CVE-2026-15308 7.5 Library accepted_risk samba
CVE-2022-37967 7.2 Archive, Bullseye, Library, Saiph not_applicable samba-common-bin → CVE-2022-37966 linked here

Related CVE (same fix)

Point this ticket’s CVE at a higher-priority / same-fix primary so you only triage one.

Other CVEs related to this one as primary:

Related CVENoteTickets
CVE-2022-37967 same product as CVE-2022-37966 Library, Archive, Bullseye, Saiph

Host OS / kernel

OS
Debian GNU/Linux 10 (buster) (10) · debian
Arch
x86_64
kernel_release
uname -r → 4.19.0-27-amd64
kernel_version
uname -v → #1 SMP Debian 4.19.316-1 (2024-06-25)

For Linux kernel CVEs, kernel_version (Debian packaging / build string) often decides fixed vs not; kernel_release is used for upstream NVD range compares.

Same CVE on other hosts

Open the ticket for this CVE on another system.

System Status Priority Updated
Library accepted_risk 4.43 2026-08-22T10:16:15Z Open
Archive accepted_risk 3.21 2026-08-22T10:16:15Z Open
Bullseye accepted_risk 3.21 2026-08-22T10:16:15Z Open

Description

Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability

Determination

ulnerability: Weak RC4-HMAC Kerberos session keys issued by Samba AD Domain Controllers
Impact: Elevation of privilege (Kerberos ticket attacks)
Affected: All Samba versions that act as an AD DC (or use Kerberos with RC4)
Fixed upstream: 4.15.13 / 4.16.8 / 4.17.4
If this Samba instance is only used as a simple file server (no AD DC role), the practical risk is significantly lower, but the code is still vulnerable.
No public access

Update status

Also apply to other systems with this CVE:

Add note only

Also add note on:

Mitigation log

2026-08-11T15:25:27Z — affects
ulnerability: Weak RC4-HMAC Kerberos session keys issued by Samba AD Domain Controllers Impact: Elevation of privilege (Kerberos ticket attacks) Affected: All Samba versions that act as an AD DC (or use Kerberos with RC4) Fixed upstream: 4.15.13 / 4.16.8 / 4.17.4
2026-08-11T15:26:27Z — affects
If this Samba instance is only used as a simple file server (no AD DC role), the practical risk is significantly lower, but the code is still vulnerable.
2026-08-11T15:31:41Z — affects
No public access

References

NVD: CVE-2022-37966