VYPR

rpm package

opensuse/samba&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/samba&distro=openSUSE%20Tumbleweed

Vulnerabilities (179)

  • CVE-2026-58224MedAug 14, 2026
    affected < 4.24.5+git.481.dba78dbdea-1.1fixed 4.24.5+git.481.dba78dbdea-1.1

    A flaw was found in Samba's CTDB, the clustered database service used by Samba. Insufficient integrity validation of received CTDB protocol packets allows malformed packets containing invalid field lengths, improperly terminated strings, or inconsistent packet sizes to be process

  • CVE-2026-58222HigJul 30, 2026
    affected < 4.24.5+git.481.dba78dbdea-1.1fixed 4.24.5+git.481.dba78dbdea-1.1

    A security flaw combining LDAP filter injection and improper authorization checks was found in Samba Active Directory Domain Controller (AD DC). When processing LDAP Compare requests, Samba fails to properly validate user-supplied attribute names and executes the resulting intern

  • CVE-2026-58216MedJul 30, 2026
    affected < 4.24.5+git.481.dba78dbdea-1.1fixed 4.24.5+git.481.dba78dbdea-1.1

    An out-of-bounds read flaw was found in Samba's Kerberos Key Distribution Center's (KDC) password change (kpasswd) service. When processing malformed ASN.1-encoded Kerberos password change request, Samba server miscalculates the structure size and attempts to read up to six bytes

  • CVE-2026-58218MedJul 30, 2026
    affected < 4.24.5+git.481.dba78dbdea-1.1fixed 4.24.5+git.481.dba78dbdea-1.1

    A flaw was found in Samba's internal DNS server where unauthenticated TKEY registration requests were added to the TKEY name cache before being rejected. A remote, unauthenticated attacker can exploit this behavior by sending a large number of TKEY requests with arbitrary names,

  • CVE-2026-3238HigJun 8, 2026
    affected < 4.23.8+git.477.f78166bceed-1.1fixed 4.23.8+git.477.f78166bceed-1.1

    A flaw was found in Samba’s WINS server component when running as an Active Directory Domain Controller. The WINS protocol handlers for certain request types did not properly validate incoming packets, allowing an unauthenticated remote attacker to trigger a NULL pointer derefere

  • CVE-2026-4408CriMay 28, 2026
    affected < 4.23.8+git.477.f78166bceed-1.1fixed 4.23.8+git.477.f78166bceed-1.1

    A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password script" feature. If this script is configured with the %u substitution character, the client-controlled username is passed

  • CVE-2026-2340MedMay 27, 2026
    affected < 4.23.8+git.477.f78166bceed-1.1fixed 4.23.8+git.477.f78166bceed-1.1

    A flaw was found in Samba’s vfs_worm module. The module is intended to provide write-once, read-many (WORM) protections by preventing modification of files after a configurable grace period. Due to insufficient validation during rename operations, an authenticated user with write

  • CVE-2026-1933HigMay 27, 2026
    affected < 4.23.8+git.477.f78166bceed-1.1fixed 4.23.8+git.477.f78166bceed-1.1

    A flaw was found in Samba’s handling of NTFS-style reparse points on shares configured with read only = yes. Due to missing SMB-layer access checks, authenticated users with underlying filesystem write permissions may create or delete reparse point metadata through SMB operations

  • CVE-2026-3012HigMay 27, 2026
    affected < 4.23.8+git.477.f78166bceed-1.1fixed 4.23.8+git.477.f78166bceed-1.1

    A flaw was found in Samba’s certificate auto-enrollment Group Policy handling. When certificate auto-enrollment is enabled, Samba may retrieve a CA certificate over an unencrypted HTTP connection and install it into the local trust store without proper verification. An attacker w

  • CVE-2026-4480CriMay 26, 2026
    affected < 4.23.8+git.477.f78166bceed-1.1fixed 4.23.8+git.477.f78166bceed-1.1

    A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the "print command" setting via the "%J" substitution character without escaping shell meta characters. A remote attacker could exploit this

  • CVE-2026-40170HigApr 16, 2026
    affected < 4.23.8+git.477.f78166bceed-1.1fixed 4.23.8+git.477.f78166bceed-1.1

    ngtcp2 is a C implementation of the IETF QUIC protocol. In versions prior to 1.22.1, ngtcp2_qlog_parameters_set_transport_params() serializes peer transport parameters into a fixed 1024-byte stack buffer without bounds checking. When qlog is enabled, a remote peer can send suffic

  • CVE-2025-10230CriNov 7, 2025
    affected < 4.22.5+git.431.dc5a539f124-1.1fixed 4.22.5+git.431.dc5a539f124-1.1

    A flaw was found in Samba, in the front-end WINS hook handling: NetBIOS names from registration packets are passed to a shell without proper validation or escaping. Unsanitized NetBIOS name data from WINS registration packets are inserted into a shell command and executed by the

  • CVE-2025-9640MedOct 15, 2025
    affected < 4.22.5+git.431.dc5a539f124-1.1fixed 4.22.5+git.431.dc5a539f124-1.1

    A flaw was found in Samba, in the vfs_streams_xattr module, where uninitialized heap memory could be written into alternate data streams. This allows an authenticated user to read residual memory content that may include sensitive data, resulting in an information disclosure vuln

  • CVE-2025-0620MedJun 6, 2025
    affected < 4.22.2+git.396.c752843dcf4-1.1fixed 4.22.2+git.396.c752843dcf4-1.1

    A flaw was found in Samba. The smbd service daemon does not pick up group membership changes when re-authenticating an expired SMB session. This issue can expose file shares until clients disconnect and then connect again.

  • CVE-2023-4154HigNov 7, 2023
    affected < 4.19.1+git.312.c912b3d2ef6-1.1fixed 4.19.1+git.312.c912b3d2ef6-1.1

    A design flaw was found in Samba's DirSync control implementation, which exposes passwords and secrets in Active Directory to privileged users and Read-Only Domain Controllers (RODCs). This flaw allows RODCs and users possessing the GET_CHANGES right to access all attributes, inc

  • CVE-2023-42669MedNov 6, 2023
    affected < 4.19.1+git.312.c912b3d2ef6-1.1fixed 4.19.1+git.312.c912b3d2ef6-1.1

    A vulnerability was found in Samba's "rpcecho" development server, a non-Windows RPC server used to test Samba's DCE/RPC stack elements. This vulnerability stems from an RPC function that can be blocked indefinitely. The issue arises because the "rpcecho" service operates with on

  • CVE-2023-3961CriNov 3, 2023
    affected < 4.19.1+git.312.c912b3d2ef6-1.1fixed 4.19.1+git.312.c912b3d2ef6-1.1

    A path traversal vulnerability was identified in Samba when processing client pipe names connecting to Unix domain sockets within a private directory. Samba typically uses this mechanism to connect SMB clients to remote procedure call (RPC) services like SAMR LSA or SPOOLSS, whic

  • CVE-2023-4091MedNov 3, 2023
    affected < 4.19.1+git.312.c912b3d2ef6-1.1fixed 4.19.1+git.312.c912b3d2ef6-1.1

    A vulnerability was discovered in Samba, where the flaw allows SMB clients to truncate files, even with read-only permissions when the Samba VFS module "acl_xattr" is configured with "acl_xattr:ignore system acls = yes". The SMB protocol allows opening files when the client reque

  • CVE-2023-42670MedNov 3, 2023
    affected < 4.19.1+git.312.c912b3d2ef6-1.1fixed 4.19.1+git.312.c912b3d2ef6-1.1

    A flaw was found in Samba. It is susceptible to a vulnerability where multiple incompatible RPC listeners can be initiated, causing disruptions in the AD DC service. When Samba's RPC server experiences a high load or unresponsiveness, servers intended for non-AD DC purposes (for

  • CVE-2023-5568MedOct 25, 2023
    affected < 4.19.2+git.322.7e9201cef5-1.1fixed 4.19.2+git.322.7e9201cef5-1.1

    A heap-based Buffer Overflow flaw was discovered in Samba. It could allow a remote, authenticated attacker to exploit this vulnerability to cause a denial of service.

Page 1 of 9