CVE-2017-12163: Debian Linux
High severity, CVSS 7.1. EPSS: 7.6% chance of exploitation in the next 30 days.
An information leak flaw was found in the way SMB1 protocol was implemented by Samba before 4.4.16, 4.5.x before 4.5.14, and 4.6.x before 4.6.8. A malicious client could use this flaw to dump server memory contents to a file on the samba share or to a shared printer, though the exact area of server memory cannot be controlled by the attacker.
Affected products
- Debian Debian Linux: version 8.0 only; version 9.0 only
- Red Hat Enterprise Linux Desktop: version 6.0 only; version 7.0 only
- Red Hat Enterprise Linux Server: version 6.0 only; version 7.0 only
- Red Hat Enterprise Linux Workstation: version 6.0 only; version 7.0 only
- Red Hat Gluster Storage: version 3.0 only
- Samba Samba: before 4.4.16 (fixed in 4.4.16); from 4.5.0, before 4.5.14 (fixed in 4.5.14); from 4.6.0, before 4.6.8 (fixed in 4.6.8)
Published 2018-07-26. Last modified 2026-06-17.