Related Vulnerabilities: CVE-2021-20254  

A security issue has been found in all versions of the Samba file server since Samba 3.6.0. A coding error converting SIDs to gids could allow unexpected group entries in a process token. This could allow unauthorized access to files. The issue is fixed in Samba 4.14.4, 4.13.8 and 4.12.15.

Severity Medium

Remote Yes

Type Access restriction bypass

Description

A security issue has been found in all versions of the Samba file server since Samba 3.6.0. A coding error converting SIDs to gids could allow unexpected group entries in a process token. This could allow unauthorized access to files. The issue is fixed in Samba 4.14.4, 4.13.8 and 4.12.15.

AVG-1893 samba 4.14.3-1 4.14.4-1 Medium Fixed

https://www.samba.org/samba/security/CVE-2021-20254.html
 https://bugzilla.samba.org/show_bug.cgi?id=14571
https://download.samba.org/pub/samba/patches/security/samba-4.14.3-security-2021-04-29.patch
https://git.samba.org/?p=samba.git;a=commitdiff;h=55b8f31679b57545d7808cae8527663d770b10bc