CVE-2019-10197: Canonical Ubuntu Linux
Critical severity, CVSS 9.1. EPSS: 3.2% chance of exploitation in the next 30 days.
A flaw was found in samba versions 4.9.x up to 4.9.13, samba 4.10.x up to 4.10.8 and samba 4.11.x up to 4.11.0rc3, when certain parameters were set in the samba configuration file. An unauthenticated attacker could use this flaw to escape the shared directory and access the contents of directories outside the share.
Affected products
- Canonical Ubuntu Linux: version 19.04 only
- Debian Debian Linux: version 10.0 only
- Samba Samba: from 4.9.0, up to and including 4.9.13; from 4.10.0, up to and including 4.10.8; version 4.9.0 only; version 4.10.0 only; version 4.11.0 only
Published 2019-09-03. Last modified 2026-06-17.