{
  "threat_severity" : "Moderate",
  "public_date" : "2021-04-29T00:00:00Z",
  "bugzilla" : {
    "description" : "samba: Negative idmap cache entries can cause incorrect group entries in the Samba file server process token",
    "id" : "1949442",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=1949442"
  },
  "cvss3" : {
    "cvss3_base_score" : "6.8",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N",
    "status" : "verified"
  },
  "cwe" : "CWE-125",
  "details" : [ "A flaw was found in samba. The Samba smbd file server must map Windows group identities (SIDs) into unix group ids (gids). The code that performs this had a flaw that could allow it to read data beyond the end of the array in the case where a negative cache entry had been added to the mapping cache. This could cause the calling code to return those values into the process token that stores the group membership for a user. The highest threat from this vulnerability is to data confidentiality and integrity.", "A flaw was found in samba. The Samba smbd file server must map Windows group identities (SIDs) into unix group ids (gids). The code that performs this had a flaw that could allow it to read data beyond the end of the array in the case where a negative cache entry had been added to the mapping cache. This could cause the calling code to return those values into the process token that stores the group membership for a user. The highest threat from this vulnerability is to data confidentiality and integrity." ],
  "acknowledgement" : "Red Hat would like to thank the Samba project for reporting this issue. Upstream acknowledges Peter Eriksson (IT Department, Linköping University) as the original reporter.",
  "affected_release" : [ {
    "product_name" : "Red Hat Enterprise Linux 7",
    "release_date" : "2021-06-08T00:00:00Z",
    "advisory" : "RHSA-2021:2313",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7",
    "package" : "samba-0:4.10.16-15.el7_9"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7.7 Advanced Update Support",
    "release_date" : "2021-10-26T00:00:00Z",
    "advisory" : "RHSA-2021:3988",
    "cpe" : "cpe:/o:redhat:rhel_aus:7.7",
    "package" : "samba-0:4.9.1-11.el7_7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7.7 Telco Extended Update Support",
    "release_date" : "2021-10-26T00:00:00Z",
    "advisory" : "RHSA-2021:3988",
    "cpe" : "cpe:/o:redhat:rhel_tus:7.7",
    "package" : "samba-0:4.9.1-11.el7_7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7.7 Update Services for SAP Solutions",
    "release_date" : "2021-10-26T00:00:00Z",
    "advisory" : "RHSA-2021:3988",
    "cpe" : "cpe:/o:redhat:rhel_e4s:7.7",
    "package" : "samba-0:4.9.1-11.el7_7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "release_date" : "2021-11-02T00:00:00Z",
    "advisory" : "RHSA-2021:4058",
    "cpe" : "cpe:/o:redhat:enterprise_linux:8",
    "package" : "samba-0:4.13.3-5.el8_4"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.2 Extended Update Support",
    "release_date" : "2021-11-30T00:00:00Z",
    "advisory" : "RHSA-2021:4866",
    "cpe" : "cpe:/o:redhat:rhel_eus:8.2",
    "package" : "samba-0:4.11.2-15.el8_2"
  }, {
    "product_name" : "Red Hat Gluster Storage 3.5 for RHEL 7",
    "release_date" : "2021-10-05T00:00:00Z",
    "advisory" : "RHSA-2021:3723",
    "cpe" : "cpe:/a:redhat:storage:3.5:samba:el7",
    "package" : "samba-0:4.11.6-112.el7rhgs"
  }, {
    "product_name" : "Red Hat Gluster Storage 3.5 for RHEL 8",
    "release_date" : "2021-10-05T00:00:00Z",
    "advisory" : "RHSA-2021:3724",
    "cpe" : "cpe:/a:redhat:storage:3.5:samba:el8",
    "package" : "samba-0:4.14.5-201.el8rhgs"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat Enterprise Linux 6",
    "fix_state" : "Out of support scope",
    "package_name" : "samba",
    "cpe" : "cpe:/o:redhat:enterprise_linux:6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 6",
    "fix_state" : "Out of support scope",
    "package_name" : "samba4",
    "cpe" : "cpe:/o:redhat:enterprise_linux:6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "fix_state" : "Not affected",
    "package_name" : "samba",
    "cpe" : "cpe:/o:redhat:enterprise_linux:9"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2021-20254\nhttps://nvd.nist.gov/vuln/detail/CVE-2021-20254\nhttps://www.samba.org/samba/security/CVE-2021-20254.html" ],
  "name" : "CVE-2021-20254",
  "csaw" : false
}