Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
Several security issues were fixed in Samba.
Software Description:
- samba: SMB/CIFS file, print, and login server for Unix
Details:
It was discovered that Samba's pam_winbind incorrectly handled home
directory ownership when mkhomedir was enabled. A local attacker could
possibly use this issue to cause a denial of service by triggering a change
in ownership of the root directory. (CVE-2026-15779)
Arjun Basnet, Douglas Bagnall, and Andrew Tridgell discovered that Samba
incorrectly handled TSIG packets with name compression. A remote attacker
could possibly use this issue to cause Samba to crash, resulting in a
denial of service. (CVE-2026-6949)
Tristan Madani discovered that Samba incorrectly handled malformed ASN.1
kpasswd packets. An authenticated user could possibly use this issue to
cause Samba to crash, resulting in a denial of service. (CVE-2026-58216)
Andrew Tridgell and Tristan Madani discovered that Samba incorrectly
handled TKEY name registration. A remote attacker ...
The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS samba 2:4.23.6+dfsg-1ubuntu2.2 Ubuntu 24.04 LTS samba 2:4.19.5+dfsg-4ubuntu9.7 Ubuntu 22.04 LTS samba 2:4.15.13+dfsg-0ubuntu1.13 In general, a standard system update will make all the necessary changes.
https://ubuntu.com/security/notices/USN-8621-1
CVE-2026-15779, CVE-2026-58216, CVE-2026-58218, CVE-2026-58221,
CVE-2026-58222, CVE-2026-58224, CVE-2026-6949
Get the latest Linux and open source security news straight to your inbox.