CVE-2021-44142
The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "...enhanced compatibility with Apple SMB clients and interoperability with...
- Published
- Feb 21, 2022
- Updated
- Apr 23, 2025
- Assigning CNA
- redhat
- Evidence observed
- Aug 25, 2026
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HHigh · next 30 days
- Percentile
- 99.5%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "...enhanced compatibility with Apple SMB clients and interoperability with a Netatalk 3 AFP fileserver." Samba versions prior to 4.13.17, 4.14.12 and 4.15.5 with vfs_fruit configured allow out-of-bounds heap read and write via specially crafted extended file attributes. A remote attacker with write access to extended file attributes can execute arbitrary code with the privileges of smbd, typically root.
Sources
4- CVE-2021-44142Exploit
Python script to detect and exploit CVE-2021-44142 in Samba servers, dumping heap cookie and pointer via single SMB connection for vulnerability verification.
- CVE-2021-44142-vulnerable-labResearch
CVE-2021-44142 vulnerable lab
Analysis and proof-of-concept for CVE-2021-44142, a Linux kernel vulnerability, providing technical details and exploitation research.
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.