Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 561
Alerts This Week
Warning Icon 1 561

Ubuntu Samba Critical Denial Of Service Vulnerabilities USN-8621-1

ubuntu
Calendar Grey July 28, 2026
Scroller Ubuntu
Multiple security issues found in Samba for Ubuntu could lead to denial of service and unauthorized access. Update now!
Ubuntu security notice USN-8621-1 addresses several vulnerabilities in Samba affecting various LTS releases, allowing potential denial of service and unauthorized modifications by ...

Summary

Several security issues were fixed in Samba.

Software Description:

- samba: SMB/CIFS file, print, and login server for Unix

Details:

It was discovered that Samba's pam_winbind incorrectly handled home

directory ownership when mkhomedir was enabled. A local attacker could

possibly use this issue to cause a denial of service by triggering a change

in ownership of the root directory. (CVE-2026-15779)

Arjun Basnet, Douglas Bagnall, and Andrew Tridgell discovered that Samba

incorrectly handled TSIG packets with name compression. A remote attacker

could possibly use this issue to cause Samba to crash, resulting in a

denial of service. (CVE-2026-6949)

Tristan Madani discovered that Samba incorrectly handled malformed ASN.1

kpasswd packets. An authenticated user could possibly use this issue to

cause Samba to crash, resulting in a denial of service. (CVE-2026-58216)

Andrew Tridgell and Tristan Madani discovered that Samba incorrectly

handled TKEY name registration. A remote attacker ...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 26.04 LTS
  samba                           2:4.23.6+dfsg-1ubuntu2.2

Ubuntu 24.04 LTS
  samba                           2:4.19.5+dfsg-4ubuntu9.7

Ubuntu 22.04 LTS
  samba                           2:4.15.13+dfsg-0ubuntu1.13

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-8621-1

CVE-2026-15779, CVE-2026-58216, CVE-2026-58218, CVE-2026-58221,

CVE-2026-58222, CVE-2026-58224, CVE-2026-6949

Severity
important
Lowest
Low
Medium
High
Critical

Ubuntu Security Notice USN-8621-1

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.