CVE-2020-25721: Samba
High severity, CVSS 8.8. EPSS: 2.2% chance of exploitation in the next 30 days.
Kerberos acceptors need easy access to stable AD identifiers (eg objectSid). Samba as an AD DC now provides a way for Linux applications to obtain a reliable SID (and samAccountName) in issued tickets.
Affected products
- Samba Samba: from 4.13.0, before 4.13.14 (fixed in 4.13.14); from 4.14.0, before 4.14.10 (fixed in 4.14.10); from 4.15.0, before 4.15.2 (fixed in 4.15.2)
Published 2022-03-16. Last modified 2026-06-17.