CVE Tracker

CVE-2022-37967 @ Library

Status
not_applicable
Priority
4.16
Match score
4.0
Risk
PrivEsc MemCorrupt Remote priv:admin
CVSS
7.2 HIGH
Reason
cpe: samba; pkgs: samba, samba-common, samba-common-bin, samba-dsdb-modules, samba-libs, samba-vfs-modules; version: in-range: samba-4.5.16+dfsg-1+deb9u4, samba-4.5.16+dfsg-1+deb9u4, samba-common-4.5.16+dfsg-1+deb9u4, samba-common-bin-4.5.16+dfsg-1+deb9u4, samba-dsdb-modules-4.5.16+dfsg-1+deb9u4, samba-libs-4.5.16+dfsg-1+deb9u4; risk:priv_esc; remote
Created
2026-08-11T10:15:46Z
Updated
2026-08-22T10:16:15Z
Closed
2026-08-11T15:29:55Z

Package interrogation (copy)

Run on the host — click to copy a command. Debian/apt

PackageCommands
samba-4.5.16+dfsg-1+deb9u4
samba-common-4.5.16+dfsg-1+deb9u4
samba-common-bin-4.5.16+dfsg-1+deb9u4
samba-dsdb-modules-4.5.16+dfsg-1+deb9u4
samba-libs-4.5.16+dfsg-1+deb9u4
samba-vfs-modules

Inventory lookup

Search package inventory across systems, then return here. Create a ticket on systems the matcher missed.

Suggestions: samba · samba-common · samba-common-bin · samba-dsdb-modules · samba-libs · samba-vfs-modules

Same product CVEs in your queue

Other tickets that look like the same product (from match reason). Relate them here to triage this CVE as the primary.

CVECVSSKEVSystemsStatus MatchedAlready related
CVE-2026-4408 9.0 Archive, Library, Saiph new samba-common-bin
CVE-2022-38023 8.1 Archive, Bullseye, Library, Saiph accepted_risk samba-common-bin
CVE-2022-37966 8.1 Archive, Bullseye, Library, Saiph accepted_risk samba-common-bin
CVE-2026-3644 7.5 Library accepted_risk samba
CVE-2026-4224 7.5 Library accepted_risk samba
CVE-2026-7210 7.5 Library accepted_risk samba → CVE-2026-15308
CVE-2026-15308 7.5 Library accepted_risk samba

Related CVE (same fix)

This CVE is subordinated to primary CVE-2022-37966 — same product as CVE-2022-37966

Host OS / kernel

OS
Debian GNU/Linux 9 (stretch) (9) · debian
Arch
x86_64
kernel_release
uname -r → 4.9.0-19-amd64
kernel_version
uname -v → #1 SMP Debian 4.9.320-2 (2022-06-30)

For Linux kernel CVEs, kernel_version (Debian packaging / build string) often decides fixed vs not; kernel_release is used for upstream NVD range compares.

Same CVE on other hosts

Open the ticket for this CVE on another system.

System Status Priority Updated
Archive not_applicable 3.08 2026-08-22T10:16:15Z Open
Bullseye not_applicable 3.08 2026-08-22T10:16:15Z Open
Saiph not_applicable 3.08 2026-08-22T10:16:15Z Open

Description

Windows Kerberos Elevation of Privilege Vulnerability

Determination

Related to primary CVE-2022-37966: same product as CVE-2022-37966

Update status

Also apply to other systems with this CVE:

Add note only

Also add note on:

Mitigation log

2026-08-11T15:29:55Z — not_applicable
Related to primary CVE-2022-37966: same product as CVE-2022-37966

References

NVD: CVE-2022-37967