CVE-2019-12435: Samba

Medium severity, CVSS 6.5. EPSS: 2.1% chance of exploitation in the next 30 days.

Samba 4.9.x before 4.9.9 and 4.10.x before 4.10.5 has a NULL pointer dereference, leading to Denial of Service. This is related to the AD DC DNS management server (dnsserver) RPC server process.

Affected products

  • Samba Samba: from 4.9.0, before 4.9.9 (fixed in 4.9.9); from 4.10.0, before 4.10.5 (fixed in 4.10.5)

Published 2019-06-19. Last modified 2026-06-17.