CVE-2020-10704: Debian Linux
High severity, CVSS 7.5. EPSS: 3.5% chance of exploitation in the next 30 days.
A flaw was found when using samba as an Active Directory Domain Controller. Due to the way samba handles certain requests as an Active Directory Domain Controller LDAP server, an unauthorized user can cause a stack overflow leading to a denial of service. The highest threat from this vulnerability is to system availability. This issue affects all samba versions before 4.10.15, before 4.11.8 and before 4.12.2.
Affected products
- Debian Debian Linux: version 9.0 only
- Fedoraproject Fedora: version 30 only; version 31 only
- Opensuse Leap: version 15.2 only
- Samba Samba: from 4.0.0, before 4.10.15 (fixed in 4.10.15); from 4.11.0, before 4.11.8 (fixed in 4.11.8); from 4.12.0, before 4.12.2 (fixed in 4.12.2)
Published 2020-05-06. Last modified 2026-06-17.