Linuxsecurity
openSUSE yast2-samba-client Command Injection Vulnerabilities Disclosed
Article Content
Multiple command injection vulnerabilities affecting the yast2-samba-client have been disclosed, with CVE-2026-25706 identified as a significant risk. This vulnerability allows OS command injection via attacker-controlled OrganizationalUnit during an interactive domain join. The affected versions include yast2-samba-client 4.4.5, 4.5.4, and 4.6.2, which impact various SUSE Linux Enterprise and openSUSE systems. Patches have been released for these vulnerabilities, and users are advised to update their systems promptly. The vulnerabilities could potentially allow attackers to execute arbitrary commands on affected systems, posing a serious risk to system integrity and confidentiality. Current status indicates that the vulnerabilities are patched, but the potential for exploitation remains a concern.
Key Points: • CVE-2026-25706 allows OS command injection via Active Directory-supplied OrganizationalUnit. • Affected versions include yast2-samba-client 4.4.5, 4.5.4, and 4.6.2. • Patches are available, and users are urged to update their systems immediately.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.