CVE-2020-10700: Fedoraproject Fedora
Medium severity, CVSS 5.3. EPSS: 2% chance of exploitation in the next 30 days.
A use-after-free flaw was found in the way samba AD DC LDAP servers, handled 'Paged Results' control is combined with the 'ASQ' control. A malicious user in a samba AD could use this flaw to cause denial of service. This issue affects all samba versions before 4.10.15, before 4.11.8 and before 4.12.2.
Affected products
- Fedoraproject Fedora: version 30 only; version 31 only; version 32 only
- Opensuse Leap: version 15.2 only
- Samba Samba: from 4.10.0, before 4.10.15 (fixed in 4.10.15); from 4.11.0, before 4.11.8 (fixed in 4.11.8); from 4.12.0, before 4.12.2 (fixed in 4.12.2)
Published 2020-05-04. Last modified 2026-06-17.