Linuxsecurity Multiple Critical Vulnerabilities Discovered in Samba Affecting Unix Systems
Article Content
- •Samba vulnerabilities allow local and remote attackers to cause denial of service.
- •Critical CVEs include CVE-2026-15779, CVE-2026-6949, and CVE-2026-58216.
- •Immediate patching is recommended for affected Unix systems to prevent exploitation.
A series of vulnerabilities have been identified in Samba, impacting Unix systems and allowing local and remote attackers to exploit them. Key issues include improper handling of directory ownership by the pam_winbind module (CVE-2026-15779), which can lead to denial of service by changing ownership of critical directories. Additionally, flaws in TSIG packet handling (CVE-2026-6949) can cause crashes in the internal DNS server, while malformed ASN.1 kpasswd packets (CVE-2026-58216) can also result in denial of service. These vulnerabilities affect various distributions, including Ubuntu and openSUSE, prompting urgent patch releases. The vulnerabilities were confirmed by multiple security advisories and pose significant risks to system integrity and availability. System administrators are advised to apply the latest patches immediately to mitigate these risks.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (15)
Following this threat?
Track Ubuntu and CVE-2024-54661 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…