Skip to content
Threat Feed
medium advisory

Samba Denial of Service Vulnerability

A vulnerability in Samba tracked as CVE-2024-4323 allows a remote, authenticated attacker to trigger a Denial of Service condition through specific request handling.

CVE search metadata

CVE search record: CVE-2024-4323. Severity: critical. CVSS: 9.8. EPSS: 28.31%. KEV: no. Product: Samba (all versions prior to patch), Samba. Brief: Samba Denial of Service Vulnerability. Brief link: https://feed.craftedsignal.io/briefs/2026-09-samba-dos/

What's new

  • 1. added coverage for Samba Sep 1, 12:04 via bsi
  • 2. added coverage for Samba Sep 1, 12:02 via bsi

A security vulnerability exists in Samba that allows a remote, authenticated attacker to cause a Denial of Service (DoS) condition. The issue stems from the improper handling of specific requests processed by the Samba service. By sending a maliciously crafted request, an attacker who has already obtained legitimate access to the network and authentication credentials can cause the service to crash or become unresponsive. This disruption affects the availability of file and print services managed by the vulnerable Samba instance. Defenders should prioritize patching affected Samba installations to the version addressed by the vendor to prevent service outages.

Impact

Successful exploitation results in the disruption of critical file and print services, leading to downtime for users and systems dependent on the affected Samba instance. This impact is primarily relevant to enterprise environments relying on Samba for SMB-based resource sharing.

Recommendation

Prioritize patching all affected Samba deployments. Refer to the official Samba security advisory for the specific corrected version corresponding to your deployment environment. Monitor system logs for unexpected Samba service crashes or restarts that may indicate attempted exploitation of CVE-2024-4323.


Immediate actions

Patch all instances of Samba to the vendor-provided corrected version.

IT Operations 48h

Threat Hunt

Identify unexpected service crash events (e.g., SIGSEGV, sudden termination) in system logs for Samba processes.

T1499 medium medium confidence hunt now

Data: Syslog, auth.log, or journald logs for smbd processes

Mitigations

Upgrade Samba to the latest patched version.

immediate IT Operations

CVE-2024-4323