Back Linuxsecurity Ubuntu Samba Critical Denial Of Service Vulnerabilities USN-8621
Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges ×
Several security issues were fixed in Samba. Software Description: - samba: SMB/CIFS file, print, and login server for Unix Details: It was discovered that Samba's pam_winbind incorrectly handled directory ownership when mkhomedir was enabled. A local attacker could possibly use this issue to cause a denial of service by triggering a change in ownership of the root directory. (CVE-2026-15779) Arjun Basnet, Douglas Bagnall, and Andrew Tridgell discovered that Samba incorrectly handled TSIG packets with name compression. A remote attacker could possibly use this issue to cause Samba to crash, resulting in a denial of service. (CVE-2026-6949) Tristan Madani discovered that Samba incorrectly handled malformed ASN.1 kpasswd packets. An authenticated user could possibly use this issue to cause Samba to crash, resulting in a denial of service. (CVE-2026-58216) Andrew Tridgell and Tristan Madani discovered that Samba incorrectly handled TKEY name registration. A remote attacker ... Read the Full Advisory
Several security issues were fixed in Samba.
Software Description:
- samba: SMB/CIFS file, print, and login server for Unix
It was discovered that Samba's pam_winbind incorrectly handled
directory ownership when mkhomedir was enabled. A local attacker could
possibly use this issue to cause a denial of service by triggering a change
in ownership of the root directory. (CVE-2026-15779)
Arjun Basnet, Douglas Bagnall, and Andrew Tridgell discovered that Samba
incorrectly handled TSIG packets with name compression. A remote attacker
could possibly use this issue to cause Samba to crash, resulting in a
denial of service. (CVE-2026-6949)
Tristan Madani discovered that Samba incorrectly handled malformed ASN.1
kpasswd packets. An authenticated user could possibly use this issue to
cause Samba to crash, resulting in a denial of service. (CVE-2026-58216)
Andrew Tridgell and Tristan Madani discovered that Samba incorrectly
handled TKEY name registration. A remote attacker ...
The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS samba 2:4.23.6+dfsg-1ubuntu2.2 Ubuntu 24.04 LTS samba 2:4.19.5+dfsg-4ubuntu9.7 Ubuntu 22.04 LTS samba 2:4.15.13+dfsg-0ubuntu1.13 In general, a standard system update will make all the necessary changes.
CVE-2026-15779, CVE-2026-58216, CVE-2026-58218, CVE-2026-58221,
CVE-2026-58222, CVE-2026-58224, CVE-2026-6949
Ubuntu Security Notice USN-8621-1
Get the latest Linux and open source security news straight to your inbox.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
