Medium severity6.5NVD Advisory· Published Aug 14, 2026· Updated Aug 31, 2026
CVE-2026-58224
CVE-2026-58224
Description
A flaw was found in Samba's CTDB, the clustered database service used by Samba. Insufficient integrity validation of received CTDB protocol packets allows malformed packets containing invalid field lengths, improperly terminated strings, or inconsistent packet sizes to be processed without adequate bounds checking. A remote attacker with access to the CTDB private network may trigger a denial of service through process crashes or excessive memory consumption and, in limited cases, disclose adjacent memory contents.
Affected products
3- osv-coords2 versionspkg:rpm/opensuse/samba&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/samba&distro=openSUSE%20Tumbleweed
< 4.22.9+git.538.af6cb4fb2e-160000.1.1+ 1 more
- (no CPE)range: < 4.22.9+git.538.af6cb4fb2e-160000.1.1
- (no CPE)range: < 4.24.5+git.481.dba78dbdea-1.1
Patches
Vulnerability mechanics
References
4- access.redhat.com/security/cve/CVE-2026-58224nvdThird Party Advisory
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingThird Party Advisory
- bugzilla.samba.org/show_bug.cginvdIssue TrackingMitigationVendor Advisory
- www.samba.org/samba/security/CVE-2026-58224-advisory.htmlnvdMailing ListVendor Advisory
News mentions
0No linked articles in our index yet.