Out-of-bounds read in Samba - CVE-2026-58216
Published: July 28, 2026 / Updated: July 29, 2026
Samba
Detailed vulnerability description
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in the KDC kpasswd packet ASN.1 parsing when processing a malformed kpasswd packet. A remote user can send a specially crafted kpasswd packet to cause a denial of service.
The invalid access is limited to 6 bytes of unallocated memory, and the accessed memory is not exposed to the user.