NULL pointer dereference in Samba - CVE-2026-3238
Published: May 27, 2026
Samba
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a NULL pointer dereference in the WINS server component when handling a crafted UDP packet. A remote attacker can send a crafted UDP packet to cause a denial of service.
The issue affects the WINS server component in the Active Directory Domain Controller code.