As per upstream advisory: winbind in version 3.6 and later implements a request to translate multiple Windows SIDs into names in one request. This was done for performance reasons: The Microsoft RPC call domain controllers offer to do this translation offer this batch operation, so it was an obvious extension to also offer this batch operation on the winbind unix domain stream socket that is available to local processes on the Samba server. Due to improper input validation a hand-crafted packet can make winbind perform a NULL pointer dereference and thus crash.
Acknowledgments: Name: the Samba project Upstream: Bas Alberts (GitHub Security Lab Team)
External References: https://www.samba.org/samba/security/CVE-2020-14323.html
Created samba tracking bugs for this issue: Affects: fedora-all [bug 1892628]
Upstream patches: samba-4.13.1: https://git.samba.org/?p=samba.git;a=commit;h=595dd9fc4162dd70ad937db8669a0fddbbba9584 https://git.samba.org/?p=samba.git;a=commit;h=0b259a48a70bde4dfd482e0720e593ae5a9c414a samba-4.12.9: https://git.samba.org/?p=samba.git;a=commit;h=f17967ad73e9c1d2bd6e0b7c181f08079d2a8214 https://git.samba.org/?p=samba.git;a=commit;h=d0ca2a63aaedf123205337aaa211426175ffcebf samba-4.11.15: https://git.samba.org/?p=samba.git;a=commit;h=e6fe5b4d64a8e1a03e1aaebafd97f313b3c94342 https://git.samba.org/?p=samba.git;a=commit;h=6093b2d815a00a577036fa001b47d7fc5514ad2c
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2020:5439 https://access.redhat.com/errata/RHSA-2020:5439
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2020-14323
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2021:1647 https://access.redhat.com/errata/RHSA-2021:1647
This issue has been addressed in the following products: Red Hat Gluster Storage 3.5 for RHEL 7 Via RHSA-2021:3723 https://access.redhat.com/errata/RHSA-2021:3723