CVE-2017-14746: Canonical Ubuntu Linux
Critical severity, CVSS 9.8. EPSS: 9.9% chance of exploitation in the next 30 days.
Use-after-free vulnerability in Samba 4.x before 4.7.3 allows remote attackers to execute arbitrary code via a crafted SMB1 request.
Affected products
- Canonical Ubuntu Linux: version 14.04 only; version 16.04 only; version 17.04 only; version 17.10 only
- Debian Debian Linux: version 8.0 only; version 9.0 only
- Red Hat Enterprise Linux Desktop: version 6.0 only; version 7.0 only
- Red Hat Enterprise Linux Server: version 6.0 only; version 7.0 only
- Red Hat Enterprise Linux Workstation: version 6.0 only; version 7.0 only
- Samba Samba: from 4.0.0, before 4.5.0 (fixed in 4.5.0); from 4.5.0, before 4.5.15 (fixed in 4.5.15); from 4.6.0, before 4.6.11 (fixed in 4.6.11); from 4.7.0, before 4.7.3 (fixed in 4.7.3)
Published 2017-11-27. Last modified 2026-06-17.