Bug 15253 - RODC doesn't reset badPwdCount reliable via an RWDC (CVE-2021-20251 regression)
Summary: RODC doesn't reset badPwdCount reliable via an RWDC (CVE-2021-20251 regression)
Status: NEW
Alias: None
Product: Samba 4.1 and newer
Classification: Unclassified
Component: AD: LDB/DSDB/SAMDB (show other bugs)
Version: 4.17.3
Hardware: All All
: P5 normal (vote)
Target Milestone: ---
Assignee: Stefan Metzmacher
QA Contact: Samba QA Contact
URL:
Keywords:
Depends on: CVE-2021-20251
Blocks:
  Show dependency treegraph
 
Reported: 2022-11-22 13:00 UTC by Stefan Metzmacher
Modified: 2022-11-25 15:11 UTC (History)
2 users (show)

See Also:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Stefan Metzmacher 2022-11-22 13:00:15 UTC
[33(192)/67 at 5m2s] samba4.ldap.rodc_rwdc.python(rodc)(rodc:local) fails randomly

This happens after commit 7b8e32efc336fb728e0c7e3dd6fbe2ed54122124
("CVE-2021-20251 auth4: Reread the user record if a bad password is noticed.")

We may read the objeGUID for the account from already free'ed memory
and may send the wrong objectGUID to the RWDC...
Comment 1 Samba QA Contact 2022-11-24 12:06:28 UTC
This bug was referenced in samba master:

1414269dccfd7cb831889cc92df35920b034457c
73ec7253139cf4704135ec7abfa6a669e158fddc
44192d5f2cae2350d7de109690799dea1a2a2e16