CVE-2025-21311

Publication date 14 January 2025

Last updated 24 July 2025


Ubuntu priority

Cvss 3 Severity Score

9.8 · Critical

Score breakdown

Windows NTLM V1 Elevation of Privilege Vulnerability

Read the notes from the security team

Mitigation

This CVE can be mitigated by switching from basic_smb_lm_auth and ntlm_smb_lm_auth to the ntml_auth helper in Samba.

Status

Package Ubuntu Release Status
squid3 25.04 plucky Not in release
24.04 LTS noble Not in release
22.04 LTS jammy Not in release
18.04 LTS bionic Ignored see notes
16.04 LTS xenial Ignored see notes
squid 25.04 plucky Ignored see notes
24.04 LTS noble Ignored see notes
22.04 LTS jammy Ignored see notes
20.04 LTS focal Ignored see notes

Notes


mdeslaur

Squid 7.1 removed the basic_smb_lm_auth and ntlm_smb_lm_auth authentication helpers and recommend using the ntml_auth helper from Samba instead. While it is unlikely LM authentication is still being used, updating Squid packages will break existing deployments. We will not be removing the helpers in Ubuntu stable releases. We recommend switching to the ntml_auth helper from Samba in environments that still require this sort of authentication.

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
squid

Severity score breakdown

Parameter Value
Base score 9.8 · Critical
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Scope Unchanged
Confidentiality High
Integrity impact High
Availability impact High
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H