Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Samba fixed CVE-2022-42898 in its 4.15.12, 4.16.7, and 4.17.3 release branches in November 2022. The integer-overflow flaw could cause denial of service or potentially remote code execution while parsing Kerberos Privilege Attribute Certificates (PACs), but Samba’s advisory limits the vulnerability to 32-bit systems. The primary concern was an authenticated attacker reaching a Samba Key Distribution Center (KDC); the issue was not an unauthenticated flaw affecting every Samba server.

What is CVE-2022-42898?

CVE-2022-42898 is an integer multiplication overflow in Kerberos libraries’ calculation of the memory allocation size needed to parse a PAC. PACs carry privilege-related information in Kerberos tickets. Samba’s advisory says the flaw affected Heimdal and MIT Kerberos libraries, including the embedded Heimdal library shipped with Samba.

On a 32-bit system, the overflow could make the allocation too small for the data being parsed. Samba described how an attacker with a forged PAC could use 16-byte chunks of attacker-controlled content to corrupt heap memory. Depending on circumstances, exploitation could cause a denial of service or potentially lead to remote code execution.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Samba published a CVSS 3.1 score of 6.4, with vector AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:L. This is a severity rating, not a measure of how likely an installation is to be attacked. The technical scope and score are in the Samba Team’s CVE-2022-42898 advisory.

#1 Best Overall
40 Pcs/20 Set Rack Mount Screws and Cage Nuts for Server Rack Cabinet, Black Carbon Steel M6 x 20 mm Screws with Nylon Washers and Cage Nuts, Rack Mount Hardware for Server Racks/Shelves/Cabinets
  • Durable Carbon Steel: Rack mount screws and cage nuts are made of high-quality carbon steel with a black finish for high strength and dependable durability.
  • Easy Installation: Clear metric threads and uniform pitch for better grip. Nylon washers help secure screws and protect equipment surfaces.
  • Organized Storage: All parts are packed in a portable storage box for easy organization and access.
  • Wide Compatibility: Fits most square-hole racks and cabinets—ideal for server racks, network cabinets, equipment enclosures, and A/V gear.
  • 20-Set Kit: Includes 20 mounting screws with nylon washers (M6 x 20 mm) and 20 square cage nuts—40 pieces in total—meeting daily install and replacement needs.

Which Samba systems were affected?

The advisory identifies versions earlier than the fixed release in each corresponding branch as affected: 4.15.12, 4.16.7, or 4.17.3. It explicitly says 64-bit systems are not impacted. Architecture and server role matter, so a version check alone does not establish whether a particular deployment was exposed.

Check What Samba’s advisory says
Architecture 32-bit systems were in scope; 64-bit systems were not impacted.
Upstream branch Versions before 4.15.12, 4.16.7, or 4.17.3 were affected in their respective branches.
Primary server role The KDC was the most vulnerable server because it parses attacker-controlled PAC data in the S4U2Proxy handler.
Secondary server role A Kerberos-enabled file server in a non-AD realm could be at secondary risk if a non-AD Heimdal KDC passed an attacker-controlled PAC in a service ticket.

For packages supplied by a Linux distribution or appliance vendor, do not rely only on the upstream version number: vendors may backport fixes without adopting the corresponding upstream release number. Check the vendor’s security advisory for the package and supported update path. Samba’s security updates and release history provide upstream release context.

How could an attacker reach the flaw?

The main concern was a Samba KDC processing a forged or attacker-controlled PAC. The contemporary report described exploitation as requiring authentication; this was not an unauthenticated, arbitrary request against any Samba installation. The KDC’s handling of PAC data in the S4U2Proxy flow is why the advisory identifies that role as the most vulnerable.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The file-server case is narrower. Samba’s advisory says a Kerberos-enabled file server could be at secondary risk in a non-AD realm when a non-AD Heimdal KDC controlling that realm passed an attacker-controlled PAC inside a service ticket. This qualification does not mean every Samba file server was directly exploitable.

Which releases fixed the vulnerability?

Samba’s November 2022 fixes were 4.15.12, 4.16.7, and 4.17.3, each fixing its corresponding branch. Administrators were advised to upgrade to the applicable fixed release or apply the patch. These are the release numbers for this historical fix, not a recommendation to deploy those versions today. For a current installation, identify its package source and consult the operating-system or appliance vendor’s advisory for a supported, patched version.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What should administrators do?

  1. Identify the system. Confirm whether the affected Samba package ran on 32-bit or 64-bit architecture, and determine whether the host served as an AD DC/KDC or as a Kerberos-enabled file server in a non-AD realm.
  2. Check the package advisory. Compare the installed package with the operating-system or appliance vendor’s security notice, accounting for any backported fix rather than comparing only its version string with upstream release numbers.
  3. Apply the vendor-supported fix. Upgrade to a package containing the correction or apply the relevant patch using the vendor’s supported procedure. Samba’s advisory states there was no workaround for 32-bit systems used as an AD DC.

The cited advisory and contemporary coverage establish the vulnerability and its 2022 fixes; they do not determine the status of a particular installation or establish current exploitation activity. SecurityWeek’s November 18, 2022 report, which covered the release at the time, is available at SecurityWeek.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.