Critical Samba Vulnerabilities Affect Multiple Ubuntu Releases

Critical Samba Vulnerabilities Affect Multiple Ubuntu Releases

First seen 26 May 2026, 23:40 UTC UbuntuLinuxsecuritylaunchpad.net 88% similarity 72.8

Article Content

Browse articles
ThreatCluster

On May 26, 2026, multiple vulnerabilities in Samba were disclosed, affecting Ubuntu 24.04 LTS, 25.10, and 26.04 LTS. Key issues include improper handling of access checks on reparse point operations (CVE-2026-1933), which could allow modification of read-only files, and a failure to block file overwrites in Samba's vfs_worm module (CVE-2026-2340). Additionally, a machine-in-the-middle attack could exploit Samba's handling of certificate auto-enrolment group policies (CVE-2026-3012). A denial of service vulnerability was also identified in Samba's Active Directory Domain Controller (CVE-2026-3238). Users are advised to update their systems to mitigate these risks. The vulnerabilities are considered critical due to their potential impact on system integrity and security.

Key Points: • Samba vulnerabilities affect Ubuntu 24.04 LTS, 25.10, and 26.04 LTS. • CVE-2026-1933 allows modification of read-only files via improper access checks. • Immediate updates are recommended to address these critical vulnerabilities.

ThreatCluster AI

Timeline

2026-05-26
Samba vulnerabilities disclosed
Multiple vulnerabilities in Samba were disclosed, affecting several Ubuntu versions and allowing potential file manipulation and denial of service.
Ubuntu
2026-05-26
Critical update released for Ubuntu
Ubuntu released updates to address critical vulnerabilities in Samba, urging users to apply them immediately.
Linuxsecurity
2026-05-26
CVE-2026-4480 published
CVE-2026-4480 was published, detailing a critical vulnerability in Samba affecting multiple Ubuntu releases.
Ubuntu

Community

Browse all →