## This update for samba fixes the following issues Security issues: * CVE-2026-1933: Missing access check on reparse point operations (bsc#1261188). * CVE-2026-2340: vfs_worm does not block directory modification (bsc#1261158). * CVE-2026-3012: group policy certificate enrollment uses http: // without validation (bsc#1261159). * CVE-2026-3238: unauthenticated udp packet crashes AD DC nbt server (bsc#1261160). * CVE-2026-4408: Remote Code Execution in SAMR (bsc#1261163). * CVE-2026-4480: Unauthenticated Remote Code Execution (bsc#1261161). Changes for samba: * network:samba:STABLE/samba: "use-kerberos=desired" broken / Dolphin requires login for Samba shares (bsc#1255755). * Samba service start times out (SElinux relabel takes too long) (bsc#1259050).
* bsc#1249058
* bsc#1255755
* bsc#1257200
* bsc#1259050
* bsc#1259667
* bsc#1261158
* bsc#1261159
* bsc#1261160
* bsc#1261161
* bsc#1261163
* bsc#1261188
Cross-
* CVE-2026-1933
* CVE-2026-2340
* CVE-2026-3012
* CVE-2026-3238
* CVE-2026-4408
* CVE-2026-4480
CVSS scores:
* CVE-2026-1933 ( SUSE ): 7.1
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N
* CVE-2026-1933 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
* CVE-2026-1933 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
* CVE-2026-1933 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-2340 ( SUSE ): 7.1
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-2340 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Get the latest Linux and open source security news straight to your inbox.