CVE-2020-25722: Canonical Ubuntu Linux

High severity, CVSS 8.8. EPSS: 1.6% chance of exploitation in the next 30 days.

Multiple flaws were found in the way samba AD DC implemented access and conformance checking of stored data. An attacker could use this flaw to cause total domain compromise.

Affected products

  • Canonical Ubuntu Linux: version 18.04 only; version 20.04 only; version 21.04 only; version 21.10 only
  • Debian Debian Linux: version 9.0 only; version 10.0 only
  • Fedoraproject Fedora: version 33 only; version 34 only; version 35 only
  • Samba Samba: from 4.0.0, before 4.13.14 (fixed in 4.13.14); from 4.14.0, before 4.14.10 (fixed in 4.14.10); from 4.15.0, before 4.15.2 (fixed in 4.15.2)

Published 2022-02-18. Last modified 2026-06-17.