CVE-2022-37967 @ Saiph
Package interrogation (copy)
Run on the host — click to copy a command. Debian/apt
| Package | Commands |
|---|---|
| samba-4.9.5+dfsg-5+deb10u5 | |
| samba-common-4.9.5+dfsg-5+deb10u5 | |
| samba-common-bin-4.9.5+dfsg-5+deb10u5 | |
| samba-dsdb-modules-4.9.5+dfsg-5+deb10u5 | |
| samba-libs-4.9.5+dfsg-5+deb10u5 | |
| samba-vfs-modules |
Inventory lookup
Search package inventory across systems, then return here. Create a ticket on systems the matcher missed.
Suggestions: samba · samba-common · samba-common-bin · samba-dsdb-modules · samba-libs · samba-vfs-modules
| System | Matches | Ticket for CVE-2022-37967 | |
|---|---|---|---|
| Archive | samba-vfs-modules 2:4.9.5+dfsg-5+deb10u5 | not_applicable open | |
| Bullseye | samba-vfs-modules 2:4.13.13+dfsg-1~deb11u8 | not_applicable open | |
| Library | samba-vfs-modules 2:4.5.16+dfsg-1+deb9u4 | not_applicable open | |
| Saiph | samba-vfs-modules 2:4.9.5+dfsg-5+deb10u5 | not_applicable open |
Same product CVEs in your queue
Other tickets that look like the same product (from match reason). Relate them here to triage this CVE as the primary.
| CVE | CVSS | KEV | Systems | Status | Matched | Already related | |
|---|---|---|---|---|---|---|---|
| CVE-2026-4408 | 9.0 | Archive, Library, Saiph | new | samba-common-bin | — | ||
| CVE-2022-38023 | 8.1 | Archive, Bullseye, Library, Saiph | accepted_risk | samba-common-bin | — | ||
| CVE-2022-37966 | 8.1 | Archive, Bullseye, Library, Saiph | accepted_risk | samba-common-bin | — | ||
| CVE-2026-3644 | 7.5 | Library | accepted_risk | samba | — | ||
| CVE-2026-4224 | 7.5 | Library | accepted_risk | samba | — | ||
| CVE-2026-7210 | 7.5 | Library | accepted_risk | samba | → CVE-2026-15308 | ||
| CVE-2026-15308 | 7.5 | Library | accepted_risk | samba | — |
Related CVE (same fix)
This CVE is subordinated to primary CVE-2022-37966 — same product as CVE-2022-37966
Host OS / kernel
uname -r → 4.19.0-27-amd64uname -v → #1 SMP Debian 4.19.316-1 (2024-06-25)For Linux kernel CVEs, kernel_version (Debian packaging / build string) often decides fixed vs not; kernel_release is used for upstream NVD range compares.
Same CVE on other hosts
Open the ticket for this CVE on another system.
| System | Status | Priority | Updated | |
|---|---|---|---|---|
| Library | not_applicable | 4.16 | 2026-08-22T10:16:15Z | Open |
| Archive | not_applicable | 3.08 | 2026-08-22T10:16:15Z | Open |
| Bullseye | not_applicable | 3.08 | 2026-08-22T10:16:15Z | Open |
Description
Windows Kerberos Elevation of Privilege Vulnerability
Determination
Related to primary CVE-2022-37966: same product as CVE-2022-37966
Update status
Add note only
Mitigation log
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-37967
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-37967
- https://security.gentoo.org/glsa/202309-06
NVD: CVE-2022-37967