Multiple Critical Vulnerabilities Discovered in Samba Affecting Unix Systems

Multiple Critical Vulnerabilities Discovered in Samba Affecting Unix Systems

First seen 28 Jul 2026, 15:16 UTC launchpad.netwww.suse.comUbuntuLinuxsecurityubuntu.com+2 72.0

Article Content

Browse articles
ThreatCluster

A series of vulnerabilities have been identified in Samba, impacting Unix systems and allowing local and remote attackers to exploit them. Key issues include improper handling of directory ownership by the pam_winbind module (CVE-2026-15779), which can lead to denial of service by changing ownership of critical directories. Additionally, flaws in TSIG packet handling (CVE-2026-6949) can cause crashes in the internal DNS server, while malformed ASN.1 kpasswd packets (CVE-2026-58216) can also result in denial of service. These vulnerabilities affect various distributions, including Ubuntu and openSUSE, prompting urgent patch releases. The vulnerabilities were confirmed by multiple security advisories and pose significant risks to system integrity and availability. System administrators are advised to apply the latest patches immediately to mitigate these risks.

Key Points: • Samba vulnerabilities allow local and remote attackers to cause denial of service. • Critical CVEs include CVE-2026-15779, CVE-2026-6949, and CVE-2026-58216. • Immediate patching is recommended for affected Unix systems to prevent exploitation.

Timeline

2024-05-30
CVE-2024-36898 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-01-31
CVE-2025-71185 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-02-04
CVE-2026-23057 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-02-14
CVE-2026-23118 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-04-24
CVE-2026-31649 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-01
CVE-2026-31773 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-01
CVE-2026-31720 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-01
CVE-2026-31781 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-08
CVE-2026-43414 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-27
CVE-2026-46073 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE