Known vulnerabilities in samba (Red Hat package)

Software CPE: cpe:2.3:o:red_hat:samba_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Total vulnerabilities: 41
Public exploits: 3
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting samba (Red Hat package) samba (Red Hat package) is affected by 41 known vulnerabilities: 11 high, 20 medium, 10 low Critical High Medium Low

Vulnerabilities (41)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU132340 - Improper Access Control
CVE-2026-1933
CWE-284 Low
No
No
4.21.3-14.el9_6.1, 4.23.5-109.el10_2 27.05.2026 SB2026052704
SB2026052705
SB2026052711
and 11 more
#VU132341 - Improper Access Control
CVE-2026-2340
CWE-284 Low
No
No
4.21.3-14.el9_6.1, 4.23.5-109.el10_2 27.05.2026 SB2026052704
SB2026052705
SB2026052707
and 17 more
#VU132342 - Improper Certificate Validation
CVE-2026-3012
CWE-295 High
No
No
4.21.3-14.el9_6.1, 4.23.5-109.el10_2 27.05.2026 SB2026052704
SB2026052705
SB2026052708
and 14 more
#VU132344 - Command injection
CVE-2026-4408
CWE-77 High
No
No
4.10.16-26.el7_9.1, 4.21.3-14.el9_6.1, 4.23.5-109.el10_2 27.05.2026 SB2026052704
SB2026052705
SB2026052707
and 20 more
#VU132345 - Command injection
CVE-2026-4480
CWE-77 High
No
No
4.10.16-26.el7_9.1, 4.21.3-14.el9_6.1, 4.23.5-109.el10_2 27.05.2026 SB2026052704
SB2026052705
SB2026052707
and 18 more
#VU131184 - Memory corruption
CVE-2026-40170
CWE-119 High
No
No
4.23.5-109.el10_2 12.05.2026 SB2026051282
SB2026051284
SB2026051285
and 5 more
#VU81875 - Improper Authorization
CVE-2023-3961
CWE-285 High
No
No
4.15.5-13.el8_6, 4.15.5-111.el9_0, 4.17.5-4.el8_8, 4.18.6-2.el8_9, 4.18.6-101.el9_3 11.10.2023 SB2023101133
SB2023101137
SB2023101155
and 28 more
#VU81872 - Permissions, Privileges, and Access Controls
CVE-2023-4091
CWE-264 Low
No
No
4.15.5-13.el8_6, 4.15.5-111.el9_0, 4.17.5-4.el8_8, 4.18.6-2.el8_9, 4.18.6-101.el9_3 11.10.2023 SB2023101133
SB2023101134
SB2023101137
and 42 more
#VU81871 - Resource Management Errors
CVE-2023-42669
CWE-399 Medium
No
No
4.15.5-13.el8_6, 4.15.5-111.el9_0, 4.17.5-4.el8_8, 4.18.6-2.el8_9, 4.18.6-101.el9_3 11.10.2023 SB2023101133
SB2023101134
SB2023101137
and 35 more
#VU78991 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2021-20316
CWE-362 Low
No
No
4.15.5-5.el8 07.08.2023 SB2023080719
SB2023091702
SB2024080686
and 4 more
#VU78577 - Out-of-bounds read
CVE-2022-2127
CWE-125 Medium
No
No
4.17.5-5.el8_8, 4.18.6-1.el8, 4.18.6-100.el9 24.07.2023 SB2023072430
SB2023072432
SB2023072433
and 34 more
#VU78576 - Exposure of sensitive information to an unauthorized actor
CVE-2023-34968
CWE-200 Low
No
No
4.17.5-5.el8_8, 4.18.6-1.el8, 4.18.6-100.el9 24.07.2023 SB2023072431
SB2023072432
SB2023072437
and 27 more
#VU78575 - Type confusion
CVE-2023-34967
CWE-843 Medium
No
No
4.17.5-5.el8_8, 4.18.6-1.el8, 4.18.6-100.el9 24.07.2023 SB2023072431
SB2023072432
SB2023072437
and 32 more
#VU78574 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2023-34966
CWE-835 Medium
No
No
4.17.5-5.el8_8, 4.17.5-105.el9_2, 4.18.6-1.el8, 4.18.6-100.el9 24.07.2023 SB2023072431
SB2023072432
SB2023072437
and 35 more
#VU78573 - Security Features
CVE-2023-3347
CWE-254 Medium
No
No
4.17.5-3.el8_8, 4.17.5-103.el9_2 24.07.2023 SB2023072431
SB2023072437
SB2023073157
and 16 more
#VU69151 - Security Features
CVE-2022-38023
CWE-254 High
No
No
4.10.4-107.el8_1, 4.10.16-24.el7_9, 4.11.2-22.el8_2, 4.13.3-11.el8_4, 4.15.5-12.el8_6, 4.15.5-110.el9_0, 4.16.4-4.el8_7, 4.16.4-103.el9_1 09.11.2022 SB2022110912
SB2022121537
SB2022121801
and 46 more
#VU67583 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2007-4559
CWE-22 High
Available
No
4.18.6-1.el8, 4.18.6-100.el9 22.09.2022 SB2007082801
SB2022120206
SB2023060825
and 68 more
#VU67270 - Use of Insufficiently Random Values
CVE-2022-1615
CWE-330 Low
No
No
4.17.5-2.el8, 4.17.5-102.el9 13.09.2022 SB2022091371
SB2022091377
SB2022091448
and 18 more
#VU65824 - Missing release of memory after effective lifetime
CVE-2022-32742
CWE-401 Low
No
No
4.15.5-10.el8_6, 4.16.4-101.el9, 4.16.5-100.el8rhgs 27.07.2022 SB2022072721
SB2022072728
SB2022072922
and 36 more
#VU60187 - Improper Link Resolution Before File Access ('Link Following')
CVE-2021-44141
CWE-59 Low
No
No
4.15.5-5.el8 31.01.2022 SB2022013112
SB2022072819
SB2022121502
and 12 more


Showing elements 1 - 20 out of 41