CVE-2020-27840: Debian Linux
High severity, CVSS 7.5. EPSS: 3.8% chance of exploitation in the next 30 days.
A flaw was found in samba. Spaces used in a string around a domain name (DN), while supposed to be ignored, can cause invalid DN strings with spaces to instead write a zero-byte into out-of-bounds memory, resulting in a crash. The highest threat from this vulnerability is to system availability.
Affected products
- Debian Debian Linux: version 9.0 only; version 10.0 only
- Fedoraproject Fedora: version 32 only; version 33 only; version 34 only
- Samba Samba: from 4.0.0, before 4.12.13 (fixed in 4.12.13); from 4.13.0, before 4.13.6 (fixed in 4.13.6); from 4.14.0, before 4.14.1 (fixed in 4.14.1)
Published 2021-05-12. Last modified 2026-06-17.