CVE-2019-19344: Canonical Ubuntu Linux

Medium severity, CVSS 6.5. EPSS: 2.8% chance of exploitation in the next 30 days.

There is a use-after-free issue in all samba 4.9.x versions before 4.9.18, all samba 4.10.x versions before 4.10.12 and all samba 4.11.x versions before 4.11.5, essentially due to a call to realloc() while other local variables still point at the original buffer.

Affected products

  • Canonical Ubuntu Linux: version 16.04 only; version 18.04 only; version 19.04 only; version 19.10 only
  • Opensuse Leap: version 15.1 only
  • Samba Samba: from 4.9.0, before 4.9.18 (fixed in 4.9.18); from 4.10.0, before 4.10.12 (fixed in 4.10.12); from 4.11.0, before 4.11.5 (fixed in 4.11.5)
  • Synology Directory Server: affected versions not specified
  • Synology Diskstation Manager: version 6.2 only
  • Synology Router Manager: version 1.2 only
  • Synology Skynas: affected versions not specified

Published 2020-01-21. Last modified 2026-06-17.