CVE-2016-2124: Canonical Ubuntu Linux

Medium severity, CVSS 5.9. EPSS: 1.8% chance of exploitation in the next 30 days.

A flaw was found in the way samba implemented SMB1 authentication. An attacker could use this flaw to retrieve the plaintext password sent over the wire even if Kerberos authentication was required.

Affected products

  • Canonical Ubuntu Linux: version 18.04 only; version 20.04 only; version 21.04 only; version 21.10 only
  • Debian Debian Linux: version 9.0 only; version 10.0 only
  • Fedoraproject Fedora: version 33 only; version 34 only; version 35 only
  • Red Hat Codeready Linux Builder: affected versions not specified
  • Red Hat Enterprise Linux: version 7.0 only; version 8.0 only
  • Red Hat Enterprise Linux Desktop: version 7.0 only
  • Red Hat Enterprise Linux Eus: version 8.2 only; version 8.4 only
  • Red Hat Enterprise Linux For IBM Z Systems: version 7.0 only; version 8.0 only
  • Red Hat Enterprise Linux For IBM Z Systems Eus: version 8.2 only; version 8.4 only
  • Red Hat Enterprise Linux For Power Big Endian: version 7.0 only
  • Red Hat Enterprise Linux For Power Little Endian: version 7.0 only; version 8.0 only
  • Red Hat Enterprise Linux For Power Little Endian Eus: version 8.2 only; version 8.4 only
  • Red Hat Enterprise Linux For Scientific Computing: version 7.0 only
  • Red Hat Enterprise Linux Resilient Storage: version 7.0 only
  • Red Hat Enterprise Linux Server: version 7.0 only
  • Red Hat Enterprise Linux Server Aus: version 8.2 only; version 8.4 only
  • Red Hat Enterprise Linux Server Tus: version 8.4 only
  • Red Hat Enterprise Linux Server Update Services For SAP Solutions: version 8.2 only; version 8.4 only
  • Red Hat Enterprise Linux Tus: version 8.2 only
  • Red Hat Enterprise Linux Workstation: version 7.0 only
  • Red Hat Gluster Storage: version 3.0 only; version 3.5 only
  • Red Hat Openstack: version 13 only; version 16.1 only; version 16.2 only
  • Red Hat Virtualization Host: version 4.0 only
  • Samba Samba: from 3.0.0, before 4.13.14 (fixed in 4.13.14); from 4.14.0, before 4.14.10 (fixed in 4.14.10); from 4.15.0, before 4.15.2 (fixed in 4.15.2)

Published 2022-02-18. Last modified 2026-06-17.