As per upstream advisory: Samba releases 4.7.0 to 4.8.0 (inclusive) contain an error which allows authentication using NTLMv1 over an SMB1 transport, even when NTLMv1 is explicitly disabled. This problem does not occur over SMB2, it is a SMB1-only issue. Normally, the use of NTLMv1 is disabled by default in favor of NTLMv2. This has been the default since Samba 4.5. A code restructuring in the NTLM authentication implementation of Samba in 4.7.0 caused this regression to occur.
Acknowledgments: Name: Vivek Das (Red Hat)
External Reference: https://www.samba.org/samba/security/CVE-2018-1139.html
Created samba tracking bugs for this issue: Affects: fedora-all [bug 1617916]
This issue has been addressed in the following products: Red Hat Gluster Storage 3.4 for RHEL 7 Via RHSA-2018:2613 https://access.redhat.com/errata/RHSA-2018:2613
This issue has been addressed in the following products: Red Hat Gluster Storage 3.4 for RHEL 6 Via RHSA-2018:2612 https://access.redhat.com/errata/RHSA-2018:2612
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2018:3056 https://access.redhat.com/errata/RHSA-2018:3056