CVE-2018-10919: Canonical Ubuntu Linux

Medium severity, CVSS 6.5. EPSS: 2.2% chance of exploitation in the next 30 days.

The Samba Active Directory LDAP server was vulnerable to an information disclosure flaw because of missing access control checks. An authenticated attacker could use this flaw to extract confidential attribute values using LDAP search expressions. Samba versions before 4.6.16, 4.7.9 and 4.8.4 are vulnerable.

Affected products

  • Canonical Ubuntu Linux: version 14.04 only; version 16.04 only; version 18.04 only
  • Debian Debian Linux: version 9.0 only
  • Samba Samba: from 4.0.0, before 4.6.16 (fixed in 4.6.16); from 4.7.0, before 4.7.9 (fixed in 4.7.9); from 4.8.0, before 4.8.4 (fixed in 4.8.4)

Published 2018-08-22. Last modified 2026-06-17.