HomeDefectsLIN1021-19420
Fixed

LIN1021-19420 : Security Advisory - samba - CVE-2025-10230

Created: Nov 9, 2025    Updated: Jun 8, 2026
Resolved Date: Jun 8, 2026
Found In Version: 10.21.20.1
Fix Version: 10.21.20.27
Severity: Standard
Applicable for: Wind River Linux LTS 21
Component/s: Userspace

Description

A flaw was found in Samba, in the front-end WINS hook handling: NetBIOS names from registration packets are passed to a shell without proper validation or escaping. Unsanitized NetBIOS name data from WINS registration packets are inserted into a shell command and executed by the Samba Active Directory Domain Controllerâ\x80\x99s wins hook, allowing an unauthenticated network attacker to achieve remote command execution as the Samba process.

CVEs