CVE-2015-7540: Canonical Ubuntu Linux
High severity, CVSS 7.5. EPSS: 7.1% chance of exploitation in the next 30 days.
The LDAP server in the AD domain controller in Samba 4.x before 4.1.22 does not check return values to ensure successful ASN.1 memory allocation, which allows remote attackers to cause a denial of service (memory consumption and daemon crash) via crafted packets.
Affected products
- Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 15.04 only; version 15.10 only
- Debian Debian Linux: version 7.0 only; version 8.0 only
- Samba Samba: from 4.0.0, before 4.1.22 (fixed in 4.1.22)
Published 2015-12-29. Last modified 2026-06-17.