Vulnerability record · CVE-2010-2063 · published 17 June 2010
CVE-2010-2063: Samba smbd SMB1 packet chaining buffer overflow
Samba · Samba
Samba's smbd has a buffer overflow in the SMB1 packet chaining implementation within the chain_reply function in process.c. A crafted field in a packet causes memory corruption, crashing the daemon or potentially allowing code execution. Samba 3.0.x before 3.3.13 is affected.
Description
Buffer overflow in the SMB1 packet chaining implementation in the chain_reply function in process.c in smbd in Samba 3.0.x before 3.3.13 allows remote attackers to cause a denial of service (memory corruption and daemon crash) or possibly execute arbitrary code via a crafted field in a packet.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityRemote, unauthenticated, low-complexity buffer overflow with a very high EPSS score, though no known active exploitation or KEV listing.
What it is
Samba's smbd has a buffer overflow in the SMB1 packet chaining implementation within the chain_reply function in process.c. A crafted field in a packet causes memory corruption, crashing the daemon or potentially allowing code execution. Samba 3.0.x before 3.3.13 is affected.
Impact
A remote attacker can crash the smbd daemon, causing denial of service, and may be able to execute arbitrary code in the context of the Samba service.
Attack surface
Reachable over the network via SMB1 traffic to smbd; the CVSS vector AV:N/AC:L/Au:N indicates no authentication or user interaction is required.
Exploitation
Not listed in CISA KEV and no ransomware usage documented; EPSS is very high (0.78558, 99.56th percentile), and references include vendor patches and advisories but no public exploit tag.
What to do
- Upgrade Samba to 3.3.13 or later, or apply the vendor patches for 3.0.37 and 3.3.12.
- Apply distribution security updates (Ubuntu USN-951-1, Debian DSA-2061, Red Hat RHSA-2010-0488).
- Restrict network access to SMB ports (TCP 139/445) to trusted hosts only.
- Disable SMB1 where possible and require SMB2 or later.
- Monitor smbd for crashes and restart under a supervisor if patching is delayed.
Detection
- Monitor smbd process crashes or core dumps and correlate with SMB traffic.
- Inspect SMB1 packet chaining fields for malformed or oversized values.
- Alert on repeated SMB connection attempts from untrusted sources to port 139/445.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2010-2063 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2010-2063), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.