CVE-2019-17455: Canonical Ubuntu Linux

Critical severity, CVSS 9.8. EPSS: 3.1% chance of exploitation in the next 30 days.

Libntlm through 1.5 relies on a fixed buffer size for tSmbNtlmAuthRequest, tSmbNtlmAuthChallenge, and tSmbNtlmAuthResponse read and write operations, as demonstrated by a stack-based buffer over-read in buildSmbNtlmAuthRequest in smbutil.c for a crafted NTLM request.

Affected products

  • Canonical Ubuntu Linux: version 14.04 only; version 16.04 only; version 18.04 only; version 20.04 only
  • Debian Debian Linux: version 8.0 only; version 9.0 only
  • Fedoraproject Fedora: version 32 only; version 33 only
  • Nongnu Libntlm: up to and including 1.5
  • Opensuse Backports Sle: version 15.0 only
  • Opensuse Leap: version 15.1 only

Published 2019-10-10. Last modified 2026-06-17.