Search CVE reports


Toggle filters

1 – 10 of 199 results


CVE-2026-4480

Medium priority

Some fixes available 5 of 8

A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the "print command" setting via the "%J" substitution character without escaping shell meta...

1 affected package

samba

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
samba Fixed Fixed Fixed Fixed Ignored
Show less packages

CVE-2026-4408

Medium priority

Some fixes available 5 of 8

A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password script" feature. If this script is configured with the %u substitution...

1 affected package

samba

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
samba Fixed Fixed Fixed Fixed Ignored
Show less packages

CVE-2026-3238

Medium priority

Some fixes available 5 of 8

A flaw was found in Samba’s WINS server component when running as an Active Directory Domain Controller. The WINS protocol handlers for certain request types did not properly validate incoming packets, allowing an unauthenticated...

1 affected package

samba

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
samba Fixed Fixed Fixed Fixed Ignored
Show less packages

CVE-2026-3012

Medium priority
Fixed

A flaw was found in Samba’s certificate auto-enrollment Group Policy handling. When certificate auto-enrollment is enabled, Samba may retrieve a CA certificate over an unencrypted HTTP connection and install it into the local...

1 affected package

samba

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
samba Fixed Fixed Not affected Not affected Not affected
Show less packages

CVE-2026-2340

Medium priority
Fixed

A flaw was found in Samba’s vfs_worm module. The module is intended to provide write-once, read-many (WORM) protections by preventing modification of files after a configurable grace period. Due to insufficient validation during...

1 affected package

samba

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
samba Fixed Fixed Fixed Not affected Not affected
Show less packages

CVE-2026-1933

Medium priority
Fixed

A flaw was found in Samba’s handling of NTFS-style reparse points on shares configured with read only = yes. Due to missing SMB-layer access checks, authenticated users with underlying filesystem write permissions may create or...

1 affected package

samba

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
samba Fixed Not affected Not affected Not affected Not affected
Show less packages

CVE-2025-9640

Low priority
Fixed

A flaw was found in Samba, in the vfs_streams_xattr module, where uninitialized heap memory could be written into alternate data streams. This allows an authenticated user to read residual memory content that may include sensitive...

1 affected package

samba

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
samba Fixed Fixed Fixed Fixed
Show less packages

CVE-2025-10230

Medium priority
Fixed

A flaw was found in Samba, in the front-end WINS hook handling: NetBIOS names from registration packets are passed to a shell without proper validation or escaping. Unsanitized NetBIOS name data from WINS registration packets are...

1 affected package

samba

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
samba Fixed Fixed Fixed Fixed
Show less packages

CVE-2025-0620

Medium priority
Fixed

A flaw was found in Samba. The smbd service daemon does not pick up group membership changes when re-authenticating an expired SMB session. This issue can expose file shares until clients disconnect and then connect again.

1 affected package

samba

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
samba Not affected Not affected Not affected Not affected
Show less packages

CVE-2020-25720

Medium priority
Vulnerable

A vulnerability was found in Samba where a delegated administrator with permission to create objects in Active Directory can write to all attributes of the newly created object, including security-sensitive attributes, even after...

1 affected package

samba

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
samba Not affected Not affected Vulnerable Vulnerable Vulnerable
Show less packages