CVE-2020-14323: Debian Linux

Medium severity, CVSS 5.5. EPSS: 0.6% chance of exploitation in the next 30 days.

A null pointer dereference flaw was found in samba's Winbind service in versions before 4.11.15, before 4.12.9 and before 4.13.1. A local user could use this flaw to crash the winbind service causing denial of service.

Affected products

  • Debian Debian Linux: version 9.0 only
  • Fedoraproject Fedora: version 32 only; version 33 only
  • Opensuse Leap: version 15.1 only; version 15.2 only
  • Samba Samba: from 3.6.0, before 4.11.15 (fixed in 4.11.15); from 4.12.0, before 4.12.9 (fixed in 4.12.9); from 4.13.0, before 4.13.1 (fixed in 4.13.1)

Published 2020-10-29. Last modified 2026-06-17.