CVE-2015-5252: Canonical Ubuntu Linux

High severity, CVSS 7.2. EPSS: 13.3% chance of exploitation in the next 30 days.

vfs.c in smbd in Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3, when share names with certain substring relationships exist, allows remote attackers to bypass intended file-access restrictions via a symlink that points outside of a share.

Affected products

  • Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 15.04 only; version 15.10 only
  • Debian Debian Linux: version 7.0 only; version 8.0 only
  • Samba Samba: from 3.0.0, before 4.1.22 (fixed in 4.1.22); from 4.2.0, before 4.2.7 (fixed in 4.2.7); from 4.3.0, before 4.3.3 (fixed in 4.3.3)

Published 2015-12-29. Last modified 2026-06-17.