CVE-2022-32745
Samba vulnerability analysis and mitigation

Overview

A vulnerability (CVE-2022-32745) was discovered in Samba that affects versions 4.16, 4.15.2, 4.14.10, 4.13.14, and later. The flaw allows Samba AD users to cause the server to access uninitialized data with an LDAP add or modify request, which typically results in a segmentation fault. The vulnerability was disclosed and patches were made available through official Samba security channels (Samba Security).

Technical details

The vulnerability stems from incorrect values used as the limit for a loop and as the 'count' parameter to memcpy(). When the server receives a specially crafted message, it leaves an array of structures partially uninitialized or accesses an arbitrary element beyond the end of an array. The vulnerability has been assigned a CVSS v3.1 base score of 5.4 (AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L) (Samba Security).

Impact

The primary impact of this vulnerability includes server segmentation faults and corresponding loss of availability. Additionally, depending on the contents of the uninitialized memory, there may be potential confidentiality implications where sensitive data could be exposed (Samba Security).

Mitigation and workarounds

No workarounds are available for this vulnerability. The recommended solution is to upgrade to Samba versions 4.16.4, 4.15.9, or 4.14.14, which have been released as security updates to address this issue. Patches have been made available through the official Samba security channel (Samba Security).

Additional resources


SourceThis report was generated using AI

Related Samba vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-10230CRITICAL10
  • SambaSamba
  • samba-libs-python3
NoYesNov 07, 2025
CVE-2020-25720HIGH7.5
  • SambaSamba
  • ctdb
NoYesNov 17, 2024
CVE-2025-0620MEDIUM4.9
  • SambaSamba
  • samba-client-libs
NoYesJun 06, 2025
CVE-2025-9640MEDIUM4.3
  • SambaSamba
  • libwbclient
NoYesOct 15, 2025
CVE-2025-58160LOW2.3
  • RustRust
  • rust-tracing-subscriber+matchers-devel
NoYesAug 29, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management