CVE-2019-14902: Canonical Ubuntu Linux

Medium severity, CVSS 5.4. EPSS: 1.4% chance of exploitation in the next 30 days.

There is an issue in all samba 4.11.x versions before 4.11.5, all samba 4.10.x versions before 4.10.12 and all samba 4.9.x versions before 4.9.18, where the removal of the right to create or modify a subtree would not automatically be taken away on all domain controllers.

Affected products

  • Canonical Ubuntu Linux: version 16.04 only; version 18.04 only; version 19.04 only; version 19.10 only
  • Debian Debian Linux: version 9.0 only
  • Opensuse Leap: version 15.1 only
  • Samba Samba: from 4.0.0, before 4.9.18 (fixed in 4.9.18); from 4.10.0, before 4.10.12 (fixed in 4.10.12); from 4.11.0, before 4.11.5 (fixed in 4.11.5)

Published 2020-01-21. Last modified 2026-06-17.