Search CVE reports


Toggle filters

1 – 10 of 206 results


CVE-2026-6949

Medium priority

Some fixes available 3 of 7

TSIG packet with name compression can crash DNS. Incorrect size calculations when a TSIG record contains compressed names can lead to a large out-of-bounds write causing the server to crash.

1 affected package

samba

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
samba Fixed Fixed Fixed Needs evaluation Needs evaluation
Show less packages

CVE-2026-58224

Medium priority

Some fixes available 3 of 7

The CTDB protocol has bounds checking issues. CTDB fails to do integrity checking of received packets. This includes failure to check field lengths against packet lengths when unmarshalling packets.

1 affected package

samba

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
samba Fixed Fixed Fixed Needs evaluation Needs evaluation
Show less packages

CVE-2026-58222

Medium priority

Some fixes available 3 of 7

A security flaw combining LDAP filter injection and improper authorization checks was found in Samba Active Directory Domain Controller (AD DC). When processing LDAP Compare requests, Samba fails to properly validate user-supplied...

1 affected package

samba

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
samba Fixed Fixed Fixed Needs evaluation Needs evaluation
Show less packages

CVE-2026-58221

Medium priority

Some fixes available 3 of 7

Samba AD authenticated LDAP access domain takeover. Samba AD low-privilege authenticated LDAP access allows modifications to internal LDB special DNs, which permits a domain takeover.

1 affected package

samba

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
samba Fixed Fixed Fixed Needs evaluation Needs evaluation
Show less packages

CVE-2026-58218

Medium priority

Some fixes available 3 of 7

A flaw was found in Samba's internal DNS server where unauthenticated TKEY registration requests were added to the TKEY name cache before being rejected. A remote, unauthenticated attacker can exploit this behavior by sending a...

1 affected package

samba

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
samba Fixed Fixed Fixed Needs evaluation Needs evaluation
Show less packages

CVE-2026-58216

Medium priority

Some fixes available 3 of 7

An out-of-bounds read flaw was found in Samba's Kerberos Key Distribution Center's (KDC) password change (kpasswd) service. When processing malformed ASN.1-encoded Kerberos password change request, Samba server miscalculates the...

1 affected package

samba

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
samba Fixed Fixed Fixed Needs evaluation Needs evaluation
Show less packages

CVE-2026-15779

Medium priority

Some fixes available 3 of 7

A flaw was found in samba's pam_winbind. When mkhomedir is enabled, pam_winbind chowns the target account's home directory without validating the path is not a critical system directory such as /. On affected systems, accounts...

1 affected package

samba

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
samba Fixed Fixed Fixed Needs evaluation Needs evaluation
Show less packages

CVE-2026-4480

Medium priority

Some fixes available 5 of 8

A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the "print command" setting via the "%J" substitution character without escaping shell meta...

1 affected package

samba

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
samba Fixed Fixed Fixed Fixed Ignored
Show less packages

CVE-2026-4408

Medium priority

Some fixes available 5 of 8

A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password script" feature. If this script is configured with the %u substitution...

1 affected package

samba

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
samba Fixed Fixed Fixed Fixed Ignored
Show less packages

CVE-2026-3238

Medium priority

Some fixes available 5 of 8

A flaw was found in Samba’s WINS server component when running as an Active Directory Domain Controller. The WINS protocol handlers for certain request types did not properly validate incoming packets, allowing an unauthenticated...

1 affected package

samba

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
samba Fixed Fixed Fixed Fixed Ignored
Show less packages