Critical Samba Security Update for Fedora 44 Addresses Multiple CVEs

Critical Samba Security Update for Fedora 44 Addresses Multiple CVEs

First seen 2 Jun 2026, 05:52 UTC Linuxsecurity 84% similarity 72.8

Article Content

Browse articles
ThreatCluster

On May 28, 2026, Fedora released an update to Samba 4.24.3, addressing several critical vulnerabilities including CVE-2026-4480, which allows remote code execution via the printing subsystem. Other vulnerabilities fixed include CVE-2026-2340, CVE-2026-3012, CVE-2026-1933, CVE-2026-4408, and CVE-2026-3238, affecting various functionalities of Samba. The vulnerabilities were published between May 26 and May 28, 2026, with the most severe allowing attackers to execute arbitrary code. Users of Fedora 44 and FreeIPA are advised to update their systems immediately to mitigate these risks. The vulnerabilities were confirmed by multiple bug reports and are considered serious threats to system security. The update can be installed using the 'dnf' update program, with specific commands provided for users.

Key Points: • Fedora 44 users must update Samba to version 4.24.3 to patch critical vulnerabilities. • CVE-2026-4480 allows remote code execution through an unescaped job description in the printing subsystem. • Multiple CVEs were addressed in this update, highlighting significant security risks in Samba.

ThreatCluster AI

Timeline

2026-05-26
CVE-2026-4480 published
CVE-2026-4480 disclosed, allowing remote code execution in Samba's printing subsystem.
Linuxsecurity
2026-05-27
CVE-2026-3012 and CVE-2026-1933 published
CVE-2026-3012 and CVE-2026-1933 published, affecting Samba's group policy and access checks.
Linuxsecurity
2026-05-27
CVE-2026-2340 published
CVE-2026-2340 published, revealing a flaw in Samba's vfs_worm that does not block directory modifications.
Linuxsecurity
2026-05-28
CVE-2026-4408 published
CVE-2026-4408 published, addressing a vulnerability in Samba's handling of access checks.
Linuxsecurity
2026-05-28
Samba 4.24.3 released
Fedora released Samba 4.24.3 to address multiple critical vulnerabilities, urging users to update.
Linuxsecurity

Community

Browse all →