Vulnerability record · CVE-2013-4124 · published 6 August 2013
CVE-2013-4124: Samba smbd integer overflow in read_nttrans_ea_list causes DoS
Canonical · Ubuntu Linux
Samba's smbd contains an integer overflow in the read_nttrans_ea_list function in nttrans.c. A malformed packet triggers excessive memory consumption, allowing a remote unauthenticated attacker to deny service to the SMB daemon. The flaw affects Samba 3.x before 3.5.22, 3.6.x before 3.6.17, and 4.x before 4.0.8.
Description
Integer overflow in the read_nttrans_ea_list function in nttrans.c in smbd in Samba 3.x before 3.5.22, 3.6.x before 3.6.17, and 4.x before 4.0.8 allows remote attackers to cause a denial of service (memory consumption) via a malformed packet.
AV:N/AC:L/Au:N/C:N/I:N/A:P
Automated analysis
high priorityRemote unauthenticated denial of service with a high EPSS score and widely deployed affected Samba versions, though impact is limited to availability.
What it is
Samba's smbd contains an integer overflow in the read_nttrans_ea_list function in nttrans.c. A malformed packet triggers excessive memory consumption, allowing a remote unauthenticated attacker to deny service to the SMB daemon. The flaw affects Samba 3.x before 3.5.22, 3.6.x before 3.6.17, and 4.x before 4.0.8.
Impact
An attacker can exhaust memory on the Samba server, degrading or halting SMB file and print services for all users. The CVSS vector shows no confidentiality or integrity impact, only partial availability loss.
Attack surface
Reachable over the network via a crafted SMB packet to smbd; the AV:N/AC:L/Au:N vector indicates no authentication and no user interaction are required.
Exploitation
Not listed in CISA KEV and no ransomware associations are documented, but EPSS is high at roughly 0.69 (99.3rd percentile), suggesting meaningful likelihood of attempted exploitation. A vendor patch reference is present.
What to do
- Upgrade Samba to 3.5.22, 3.6.17, 4.0.8 or later, or apply the vendor security patch.
- Apply distribution updates from Red Hat, Fedora, Ubuntu, openSUSE, Gentoo or Mandriva advisories for this CVE.
- Restrict network access to SMB ports (139/445) to trusted hosts and segments where feasible.
- Monitor smbd memory usage and restart or rate-limit if abnormal growth is observed.
Detection
- Alert on smbd memory growth or OOM events correlated with SMB traffic.
- Inspect SMB traffic for malformed NT Transact (NTTRANS) EA list requests.
- Review Samba logs for crashes, restarts or resource exhaustion around SMB sessions.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2013-4124 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2013-4124), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.