• Welcome to TechPowerUp Forums, Guest! Please check out our forum guidelines for info related to our community.

Numerous Security Fixes Implemented for SAMBA, Kernel and Various Plugins in ASUSTOR's Security Investigation

btarunr

Editor & Senior Moderator
Staff member
Joined
Oct 9, 2007
Messages
46,439 (7.66/day)
Location
Hyderabad, India
System Name RBMK-1000
Processor AMD Ryzen 7 5700G
Motherboard ASUS ROG Strix B450-E Gaming
Cooling DeepCool Gammax L240 V2
Memory 2x 8GB G.Skill Sniper X
Video Card(s) Palit GeForce RTX 2080 SUPER GameRock
Storage Western Digital Black NVMe 512GB
Display(s) BenQ 1440p 60 Hz 27-inch
Case Corsair Carbide 100R
Audio Device(s) ASUS SupremeFX S1220A
Power Supply Cooler Master MWE Gold 650W
Mouse ASUS ROG Strix Impact
Keyboard Gamdias Hermes E2
Software Windows 11 Pro
In order to strengthen the implementation of protection from malware attacks, ASUSTOR continuously upgrades ADM system in order to bring security and safety to users. ASUSTOR recognizes the spread of malware is an increasingly large problem for data security and ransomware resembling Deadbolt is a wakeup call for customers and providers. In light of this, ASUSTOR will increase its commitment to identify and patch potential vulnerabilities with consistent updates to be ahead of threats to data.

The latest version of ADM updates Samba, Linux packages and Linux kernel to strengthen ADM's security for the best customer experience. In addition to updating ADM to fix OS vulnerabilities, third party portions of the OS have been updated for greater security. While these security updates help keep ADM more secure than it has ever been, making 3-2-1-compliant backups is the only way to ensure data is secure from most practical risks.



New security updates for ADM:
  • Updated SAMBA to fix the following vulnerabilities: CVE-2022-32742, CVE-2022-2031, CVE-2022-32744, CVE-2022-32745, CVE-2022-32746.
  • Fixed the following Linux kernel vulnerabilities: CVE-2019-18282, CVE-2019-19527, CVE-2019-19532, CVE-2019-19537, CVE-2020-12770, CVE-2021-0605, CVE-2021-20317, CVE-2021-20321, CVE-2021-29154, CVE-2021-29650, CVE-2021-34556, CVE-2021-35477, CVE-2021-3732, CVE-2021-3753, CVE-2021-39633, CVE-2021-39698, CVE-2021-4149, CVE-2021-4203, CVE-2021-45868, CVE-2022-0185, CVE-2022-0330, CVE-2022-0617, CVE-2022-1011, CVE-2022-1048, CVE-2022-1055, CVE-2022-1353, CVE-2022-20008, CVE-2022-27666, CVE-2022-28893, CVE-2022-29582.
  • Updated GnuTLS to fix the following vulnerabilities: CVE-2020-24659, CVE-2021-20231, CVE-2021-20232.
  • Updated Nettle to fix the following vulnerabilities: CVE-2021-3580, CVE-2021-20305.
  • Updated Avahi to fix the following vulnerabilities: CVE-2021-3502, CVE-2021-3468.

View at TechPowerUp Main Site
 
Joined
Jul 29, 2022
Messages
383 (0.59/day)
What they need to fix is the lack of ability to use a drive without formatting it first. This makes their devices completely unusable.
 

bug

Joined
May 22, 2015
Messages
13,262 (4.04/day)
Processor Intel i5-12600k
Motherboard Asus H670 TUF
Cooling Arctic Freezer 34
Memory 2x16GB DDR4 3600 G.Skill Ripjaws V
Video Card(s) EVGA GTX 1060 SC
Storage 500GB Samsung 970 EVO, 500GB Samsung 850 EVO, 1TB Crucial MX300 and 2TB Crucial MX500
Display(s) Dell U3219Q + HP ZR24w
Case Raijintek Thetis
Audio Device(s) Audioquest Dragonfly Red :D
Power Supply Seasonic 620W M12
Mouse Logitech G502 Proteus Core
Keyboard G.Skill KM780R
Software Arch Linux + Win10
I don't get it. Did they just discover apt update/dnf upgrade? Or they had that, but their repos just lagged behind?
 

TheLostSwede

News Editor
Joined
Nov 11, 2004
Messages
16,165 (2.27/day)
Location
Sweden
System Name Overlord Mk MLI
Processor AMD Ryzen 7 7800X3D
Motherboard Gigabyte X670E Aorus Master
Cooling Noctua NH-D15 SE with offsets
Memory 32GB Team T-Create Expert DDR5 6000 MHz @ CL30-34-34-68
Video Card(s) Gainward GeForce RTX 4080 Phantom GS
Storage 1TB Solidigm P44 Pro, 2 TB Corsair MP600 Pro, 2TB Kingston KC3000
Display(s) Acer XV272K LVbmiipruzx 4K@160Hz
Case Fractal Design Torrent Compact
Audio Device(s) Corsair Virtuoso SE
Power Supply be quiet! Pure Power 12 M 850 W
Mouse Logitech G502 Lightspeed
Keyboard Corsair K70 Max
Software Windows 10 Pro
Benchmark Scores https://valid.x86.fr/yfsd9w
I don't get it. Did they just discover apt update/dnf upgrade? Or they had that, but their repos just lagged behind?
The issue is that these pre-built NAS devices run custom operating systems that often use older kernels and older software versions, which requires custom software patches. Sometimes it takes these companies a few months to issue updates, which is far from ideal.
 

bug

Joined
May 22, 2015
Messages
13,262 (4.04/day)
Processor Intel i5-12600k
Motherboard Asus H670 TUF
Cooling Arctic Freezer 34
Memory 2x16GB DDR4 3600 G.Skill Ripjaws V
Video Card(s) EVGA GTX 1060 SC
Storage 500GB Samsung 970 EVO, 500GB Samsung 850 EVO, 1TB Crucial MX300 and 2TB Crucial MX500
Display(s) Dell U3219Q + HP ZR24w
Case Raijintek Thetis
Audio Device(s) Audioquest Dragonfly Red :D
Power Supply Seasonic 620W M12
Mouse Logitech G502 Proteus Core
Keyboard G.Skill KM780R
Software Arch Linux + Win10
The issue is that these pre-built NAS devices run custom operating systems that often use older kernels and older software versions, which requires custom software patches. Sometimes it takes these companies a few months to issue updates, which is far from ideal.
Let's be honest, they're running Linux. Sure, there's a custom WebUI and custom services on top. Neither should stop them from patching the underlying OS promptly.
 

TheLostSwede

News Editor
Joined
Nov 11, 2004
Messages
16,165 (2.27/day)
Location
Sweden
System Name Overlord Mk MLI
Processor AMD Ryzen 7 7800X3D
Motherboard Gigabyte X670E Aorus Master
Cooling Noctua NH-D15 SE with offsets
Memory 32GB Team T-Create Expert DDR5 6000 MHz @ CL30-34-34-68
Video Card(s) Gainward GeForce RTX 4080 Phantom GS
Storage 1TB Solidigm P44 Pro, 2 TB Corsair MP600 Pro, 2TB Kingston KC3000
Display(s) Acer XV272K LVbmiipruzx 4K@160Hz
Case Fractal Design Torrent Compact
Audio Device(s) Corsair Virtuoso SE
Power Supply be quiet! Pure Power 12 M 850 W
Mouse Logitech G502 Lightspeed
Keyboard Corsair K70 Max
Software Windows 10 Pro
Benchmark Scores https://valid.x86.fr/yfsd9w
Let's be honest, they're running Linux. Sure, there's a custom WebUI and custom services on top. Neither should stop them from patching the underlying OS promptly.
Sure, but when you're using an unsupported kernel and five year old versions of Samba... Then you end up having to do a lot of extra work to patch your software.
Not trying to defend these companies, simply informing about how they operate.
Have a look at QNAP's FreeBSD based software. My friend was one of the main engineers on that project, he quit, because they wouldn't listen to him and decided to use an old OS that they now have to backport everything to. It's a disaster.
 

bug

Joined
May 22, 2015
Messages
13,262 (4.04/day)
Processor Intel i5-12600k
Motherboard Asus H670 TUF
Cooling Arctic Freezer 34
Memory 2x16GB DDR4 3600 G.Skill Ripjaws V
Video Card(s) EVGA GTX 1060 SC
Storage 500GB Samsung 970 EVO, 500GB Samsung 850 EVO, 1TB Crucial MX300 and 2TB Crucial MX500
Display(s) Dell U3219Q + HP ZR24w
Case Raijintek Thetis
Audio Device(s) Audioquest Dragonfly Red :D
Power Supply Seasonic 620W M12
Mouse Logitech G502 Proteus Core
Keyboard G.Skill KM780R
Software Arch Linux + Win10
Sure, but when you're using an unsupported kernel and five year old versions of Samba... Then you end up having to do a lot of extra work to patch your software.
Not trying to defend these companies, simply informing about how they operate.
Have a look at QNAP's FreeBSD based software. My friend was one of the main engineers on that project, he quit, because they wouldn't listen to him and decided to use an old OS that they now have to backport everything to. It's a disaster.
Oh, I know that very well.
That what I was hinting at in my initial post: Asus haven't suddenly discovered a security miracle, they simply stopped slacking off and did something they should be doing every day.

This isn't even something specific to routers. Any smart device suffers from software neglect, most of the time way worse than your router. I've even read a suggestion to place all "smart" devices on your guest network to give yourself and extra layer of isolation from crappy and exploitable software.

As for companies adamantly insisting on doing the wrong thing because "reasons"... I'm all too familiar with that.
 
Last edited:
Joined
Dec 26, 2006
Messages
3,562 (0.56/day)
Location
Northern Ontario Canada
Processor Ryzen 5700x
Motherboard Gigabyte X570S Aero G R1.1 BiosF5g
Cooling Noctua NH-C12P SE14 w/ NF-A15 HS-PWM Fan 1500rpm
Memory Micron DDR4-3200 2x32GB D.S. D.R. (CT2K32G4DFD832A)
Video Card(s) AMD RX 6800 - Asus Tuf
Storage Kingston KC3000 1TB & 2TB & 4TB Corsair LPX
Display(s) LG 27UL550-W (27" 4k)
Case Be Quiet Pure Base 600 (no window)
Audio Device(s) Realtek ALC1220-VB
Power Supply SuperFlower Leadex V Gold Pro 850W ATX Ver2.52
Mouse Mionix Naos Pro
Keyboard Corsair Strafe with browns
Software W10 22H2 Pro x64
Ok. I’m a bit lost.

Is this asustor pushing out firmware with an updated Samba??
Or
Is this Samba putting out the latest or updated version for everyone to use?
 
Joined
Dec 16, 2017
Messages
2,731 (1.17/day)
Location
Buenos Aires, Argentina
System Name System V
Processor AMD Ryzen 5 3600
Motherboard Asus Prime X570-P
Cooling Cooler Master Hyper 212 // a bunch of 120 mm Xigmatek 1500 RPM fans (2 ins, 3 outs)
Memory 2x8GB Ballistix Sport LT 3200 MHz (BLS8G4D32AESCK.M8FE) (CL16-18-18-36)
Video Card(s) Gigabyte AORUS Radeon RX 580 8 GB
Storage SHFS37A240G / DT01ACA200 / WD20EZRX / MKNSSDTR256GB-3DL / LG BH16NS40 / ST10000VN0008
Display(s) LG 22MP55 IPS Display
Case NZXT Source 210
Audio Device(s) Logitech G430 Headset
Power Supply Corsair CX650M
Mouse Microsoft Trackball Optical 1.0
Keyboard HP Vectra VE keyboard (Part # D4950-63004)
Software Whatever build of Windows 11 is being served in Dev channel at the time.
Benchmark Scores Corona 1.3: 3120620 r/s Cinebench R20: 3355 FireStrike: 12490 TimeSpy: 4624
Ok. I’m a bit lost.

Is this asustor pushing out firmware with an updated Samba??
Or
Is this Samba putting out the latest or updated version for everyone to use?
The first thing. Though not sure I'd call it firmware, but I suppose it works anyway
 
Joined
Feb 18, 2022
Messages
50 (0.06/day)
Processor Ryzen 5900X
Motherboard Asus ROG CROSSHAIR VII HERO
Cooling Noctua NH-U12S
Memory 4x Kingston HyperX 16G 3000MHz
Video Card(s) Asus ROG Strix 4800
Case Inwin 909
Power Supply EVGA Supernova 750 P2
Mouse Razer Lancehead Wireless
Keyboard Razer Huntsman V2 TKL
Software Debian Linux / Win11
So nice from them to fix CVEs not only from 2022, but 2021 and 2020 too. I thought these boxes have regular updates.
 

bug

Joined
May 22, 2015
Messages
13,262 (4.04/day)
Processor Intel i5-12600k
Motherboard Asus H670 TUF
Cooling Arctic Freezer 34
Memory 2x16GB DDR4 3600 G.Skill Ripjaws V
Video Card(s) EVGA GTX 1060 SC
Storage 500GB Samsung 970 EVO, 500GB Samsung 850 EVO, 1TB Crucial MX300 and 2TB Crucial MX500
Display(s) Dell U3219Q + HP ZR24w
Case Raijintek Thetis
Audio Device(s) Audioquest Dragonfly Red :D
Power Supply Seasonic 620W M12
Mouse Logitech G502 Proteus Core
Keyboard G.Skill KM780R
Software Arch Linux + Win10
So nice from them to fix CVEs not only from 2022, but 2021 and 2020 too. I thought these boxes have regular updates.
They're regular alright. It's just that the cadence is "whenever they can be bothered".

Like @TheLostSwede said above, manufacturers use (unnecessarily) customized software, which is hard to maintain. And the further they fall back, the harder it becomes to port various fixes. Add to that people that may leave the project over time and you can start to understand why maintenance is such a nightmare, nobody wants to do it.
 
Top