SB2026072958 - Debian update for samba



SB2026072958 - Debian update for samba

Published: July 29, 2026

Security Bulletin ID SB2026072958
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 6
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Medium 67% Low 33%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 6 vulnerabilities.


1) Out-of-bounds write (CVE-ID: CVE-2026-6949)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to an out-of-bounds write in the DNS server TSIG record handling when processing a TSIG packet containing compressed names. A remote attacker can send a specially crafted TSIG packet to cause a denial of service.


2) Out-of-bounds read (CVE-ID: CVE-2026-58216)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to an out-of-bounds read in the KDC kpasswd packet ASN.1 parsing when processing a malformed kpasswd packet. A remote user can send a specially crafted kpasswd packet to cause a denial of service.

The invalid access is limited to 6 bytes of unallocated memory, and the accessed memory is not exposed to the user.


3) Resource exhaustion (CVE-ID: CVE-2026-58218)

CWE-ID: CWE-400 - Resource exhaustion

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper resource management in the DNS TKEY name cache when repeatedly registering TKEY names. A remote attacker can repeatedly register names to cause a denial of service.

The issue can flood the cache and expunge legitimate TKEYs, practically blocking DNS TSIG signing.


4) Improper access control (CVE-ID: CVE-2026-58221)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote user to escalate privileges.

The vulnerability exists due to improper access control in Samba AD internal LDB special DNs when handling authenticated LDAP access. A remote user can modify internal LDB special DNs to escalate privileges.

The issue permits a domain takeover.


5) SQL injection (CVE-ID: CVE-2026-58222)

CWE-ID: CWE-89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to filter injection and trusted-request confusion in the LDAP Compare operation when handling LDAP Compare requests. A remote user can send crafted LDAP Compare requests to disclose sensitive information.

Confidential Active Directory attributes, including KDS root keys, can be queried by bypassing access checks.


6) Input validation error (CVE-ID: CVE-2026-58224)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper input validation in the CTDB protocol packet unmarshalling when processing received packets. A remote attacker can send a specially crafted packet to cause a denial of service.

The issue includes missing integrity checks and failure to verify field lengths against packet lengths.


Remediation

Install update from vendor's website.