Echo: samba: security update to 2:4.13.14+dfsg-1

high Tenable Self-Hosted Container Security Plugin ID 460375

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In DCE/RPC it is possible to share the handles (cookies for resource state) between multiple connections
via a mechanism called 'association groups'. These handles can reference connections to our sam.ldb
database. However while the database was correctly shared, the user credentials state was only pointed at,
and when one connection within that association group ended, the database would be left pointing at an
invalid 'struct session_info'. The most likely outcome here is a crash, but it is possible that the use-
after-free could instead allow different user state to be pointed at and this might allow more privileged
access. (CVE-2021-3738)

Solution

Update the samba library and its related packages to version 2:4.13.14+dfsg-1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2021-3738

Plugin Details

Severity: High

ID: 460375

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.12

CVSS v2

Risk Factor: Medium

Base Score: 6.5

Temporal Score: 4.8

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:P

CVSS Score Source: CVE-2021-3738

CVSS v3

Risk Factor: High

Base Score: 8.8

Temporal Score: 7.7

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 6/2/2026

Vulnerability Publication Date: 11/9/2021

Reference Information

CVE: CVE-2021-3738

IAVA: 2021-A-0554