Medium severity5.3NVD Advisory· Published Jul 30, 2026· Updated Jul 30, 2026
CVE-2026-58218
CVE-2026-58218
Description
A flaw was found in Samba's internal DNS server where unauthenticated TKEY registration requests were added to the TKEY name cache before being rejected. A remote, unauthenticated attacker can exploit this behavior by sending a large number of TKEY requests with arbitrary names, exhausting the cache and evicting legitimate TKEY entries. This can prevent legitimate TSIG authentication for signed DNS queries, resulting in a denial of service.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- osv-coords2 versionspkg:rpm/opensuse/samba&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/samba&distro=openSUSE%20Tumbleweed
< 4.22.9+git.538.af6cb4fb2e-160000.1.1+ 1 more
- (no CPE)range: < 4.22.9+git.538.af6cb4fb2e-160000.1.1
- (no CPE)range: < 4.24.5+git.481.dba78dbdea-1.1
Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.