Buffer overflow in Samba - CVE-2026-40170

 

Buffer overflow in Samba - CVE-2026-40170

Published: May 12, 2026


Vulnerability identifier: #VU131184
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-40170
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to memory corruption in thirdparty ngtcp2 when processing network traffic. A remote attacker can send specially crafted network traffic to execute arbitrary code.


Affected software

Samba
Debian Linux
Fedora
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Ubuntu
ngtcp2 (Ubuntu package)
ngtcp2 (Debian package)
ngtcp2
samba (Red Hat package)

How to mitigate CVE-2026-40170

Install security update from vendor's website.

Samba - update to 4.24.2
ngtcp2 (Ubuntu package) - addressed in versions 0.1.0+dfsg-1ubuntu0.1~esm1, 0.12.1+dfsg-1+deb12u1build0.24.04.1, 1.11.0-1+deb13u1build0.25.10.1, 1.16.0-1ubuntu0.1
ngtcp2 (Debian package) - addressed in versions 0.12.1+dfsg-1+deb12u1, 1.11.0-1+deb13u1
ngtcp2 - addressed in versions 1.22.1-1.el9, 1.22.1-1.el10_3, 1.22.1-1.fc43, 1.22.1-1.fc44
samba (Red Hat package) - update to 4.23.5-109.el10_2

External References

Related Security Bulletins