CVE-2015-0240: Canonical Ubuntu Linux

High severity, CVSS 10.0. EPSS: 87.6% chance of exploitation in the next 30 days.

The Netlogon server implementation in smbd in Samba 3.5.x and 3.6.x before 3.6.25, 4.0.x before 4.0.25, 4.1.x before 4.1.17, and 4.2.x before 4.2.0rc5 performs a free operation on an uninitialized stack pointer, which allows remote attackers to execute arbitrary code via crafted Netlogon packets that use the ServerPasswordSet RPC API, as demonstrated by packets reaching the _netr_ServerPasswordSet function in rpc_server/netlogon/srv_netlog_nt.c.

Affected products

  • Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 14.10 only
  • Novell Suse Linux Enterprise Desktop: version 12 only
  • Novell Suse Linux Enterprise Server: version 12 only
  • Novell Suse Linux Enterprise Software Development Kit: version 12 only
  • Red Hat Enterprise Linux: version 5 only; version 6.0 only; version 7.0 only
  • Samba Samba: version 3.5.0 only; version 3.5.1 only; version 3.5.2 only; version 3.5.3 only; version 3.5.4 only; version 3.5.5 only; …

Published 2015-02-24. Last modified 2026-06-17.