Echo: samba: security update to 2:4.16.0+dfsg-2

low Tenable Cloud Security Plugin ID 463751

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- All versions of Samba prior to 4.13.16 are vulnerable to a malicious client using an SMB1 or NFS race to
allow a directory to be created in an area of the server file system not exported under the share
definition. Note that SMB1 has to be enabled, or the share also available via NFS in order for this attack
to succeed. (CVE-2021-43566)

Solution

Update the samba library and its related packages to version 2:4.16.0+dfsg-2 or later.

See Also

https://advisory.echohq.com/cve/CVE-2021-43566

Plugin Details

Severity: Low

ID: 463751

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Low

Score: 1.2

Percentile: 0.01

CVSS v2

Risk Factor: Low

Base Score: 1.2

Temporal Score: 0.9

Vector: CVSS2#AV:L/AC:H/Au:N/C:N/I:P/A:N

CVSS Score Source: CVE-2021-43566

CVSS v3

Risk Factor: Low

Base Score: 2.5

Temporal Score: 2.3

Vector: CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 6/2/2026

Vulnerability Publication Date: 11/9/2021

Reference Information

CVE: CVE-2021-43566

IAVA: 2022-A-0020