CVE-2026-58218

Aliases:UBUNTU-CVE-2026-58218DEBIAN-CVE-2026-58218
Awaiting Analysis
Published: 30 Jul 2026, 14:01
Last modified:30 Jul 2026, 17:37

Vulnerability Summary

Overall Risk (default)
low
21/100
CVSS Score
5.3 MEDIUM
v3.1 (cve.org)
EPSS Score
0.62% LOW
1% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

30 Jul 2026, 14:01
Published
Vulnerability first disclosed
30 Jul 2026, 17:37
Last Modified
Vulnerability information updated

Description

A flaw was found in Samba's internal DNS server where unauthenticated TKEY registration requests were added to the TKEY name cache before being rejected. A remote, unauthenticated attacker can exploit this behavior by sending a large number of TKEY requests with arbitrary names, exhausting the cache and evicting legitimate TKEY entries. This can prevent legitimate TSIG authentication for signed DNS queries, resulting in a denial of service.

CVSS Metrics

  • v3.1MEDIUMScore: 5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

EPSS Trends

Current EPSS score: 0.62% Percentile: 48%

Techniques & Countermeasures

  • CWE-410Insufficient Resource Pool

    The product's resource pool is not large enough to handle peak demand, which allows an attacker to prevent others from accessing the resource by using a (relatively) large number of requests for resources.

Affected Systems

  • debiansamba

    all | all | < 2:4.22.10+dfsg-0+deb13u2 | < 2:4.24.5+dfsg-1

  • ubuntusamba

    all | < 2:4.15.13+dfsg-0ubuntu1.13 | < 2:4.19.5+dfsg-4ubuntu9.7 | < 2:4.23.6+dfsg-1ubuntu2.2

References (8)