CVE-2019-19344: Canonical Ubuntu Linux
Medium severity, CVSS 6.5. EPSS: 2.8% chance of exploitation in the next 30 days.
There is a use-after-free issue in all samba 4.9.x versions before 4.9.18, all samba 4.10.x versions before 4.10.12 and all samba 4.11.x versions before 4.11.5, essentially due to a call to realloc() while other local variables still point at the original buffer.
Affected products
- Canonical Ubuntu Linux: version 16.04 only; version 18.04 only; version 19.04 only; version 19.10 only
- Opensuse Leap: version 15.1 only
- Samba Samba: from 4.9.0, before 4.9.18 (fixed in 4.9.18); from 4.10.0, before 4.10.12 (fixed in 4.10.12); from 4.11.0, before 4.11.5 (fixed in 4.11.5)
- Synology Directory Server: affected versions not specified
- Synology Diskstation Manager: version 6.2 only
- Synology Router Manager: version 1.2 only
- Synology Skynas: affected versions not specified
Published 2020-01-21. Last modified 2026-06-17.