[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-OPENSUSE-SU-2026:20905-1":6},{"stargazers_count":4,"fetched_at":5},7,"2026-08-01T16:22:42.503Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":11,"aliases":12,"duplicate_of":9,"upstream":13,"downstream":26,"duplicates":27,"related":28,"reserved_at":9,"published_at":35,"modified_at":36,"state":9,"summary":37,"references_raw":39,"kevs":111,"epss":9,"epss_history":112,"metrics":113,"affected":114},"OPENSUSE-SU-2026:20905-1","Security update for samba\n\nThis update for samba fixes the following issues\n\nSecurity issues:\n\n- CVE-2026-1933: Missing access check on reparse point operations (bsc#1261188).\n- CVE-2026-2340: vfs_worm does not block directory modification (bsc#1261158).\n- CVE-2026-3012: group policy certificate enrollment uses http: // without validation (bsc#1261159).\n- CVE-2026-3238: unauthenticated udp packet crashes AD DC nbt server (bsc#1261160).\n- CVE-2026-4408: Remote Code Execution in SAMR (bsc#1261163).\n- CVE-2026-4480: Unauthenticated Remote Code Execution (bsc#1261161).\n\nChanges for samba:\n\n- network:samba:STABLE/samba: \"use-kerberos=desired\" broken / Dolphin requires login for Samba shares (bsc#1255755).\n- Samba service start times out (SElinux relabel takes too long) (bsc#1259050).\n- samba-ad-dc-libs packages is missing a DLZ plugin for bind 9.20 (bsc#1249058).\n- VFS_Snapper does not show previous file versions in subdirectories. (bsc#1259667).\n- Updated to 4.22.9\n",null,[],[],[],[14,16,18,20,22,24],{"_key":15},"CVE-2026-1933",{"_key":17},"CVE-2026-2340",{"_key":19},"CVE-2026-3012",{"_key":21},"CVE-2026-3238",{"_key":23},"CVE-2026-4408",{"_key":25},"CVE-2026-4480",[],[],[29,30,31,32,33,34],{"_key":15},{"_key":17},{"_key":19},{"_key":21},{"_key":23},{"_key":25},"2026-06-05T08:45:16Z","2026-06-09T18:24:31.023299454Z",{"cisa_kev":38,"cisa_ransomware":38,"cisa_vendor":9,"epss_severity":9,"epss_score":9,"severity":9,"severity_score":9,"severity_version":9,"severity_source":9,"severity_vector":9,"severity_status":9},false,[40,46,50,54,58,62,66,70,74,78,82,86,91,95,99,103,107],{"url":41,"sources":42,"tags":44},"https://bugzilla.suse.com/1249058",[43],"osv_opensuse",[45],"REPORT",{"url":47,"sources":48,"tags":49},"https://bugzilla.suse.com/1255755",[43],[45],{"url":51,"sources":52,"tags":53},"https://bugzilla.suse.com/1257200",[43],[45],{"url":55,"sources":56,"tags":57},"https://bugzilla.suse.com/1259050",[43],[45],{"url":59,"sources":60,"tags":61},"https://bugzilla.suse.com/1259667",[43],[45],{"url":63,"sources":64,"tags":65},"https://bugzilla.suse.com/1261158",[43],[45],{"url":67,"sources":68,"tags":69},"https://bugzilla.suse.com/1261159",[43],[45],{"url":71,"sources":72,"tags":73},"https://bugzilla.suse.com/1261160",[43],[45],{"url":75,"sources":76,"tags":77},"https://bugzilla.suse.com/1261161",[43],[45],{"url":79,"sources":80,"tags":81},"https://bugzilla.suse.com/1261163",[43],[45],{"url":83,"sources":84,"tags":85},"https://bugzilla.suse.com/1261188",[43],[45],{"url":87,"sources":88,"tags":89},"https://www.suse.com/security/cve/CVE-2026-1933",[43],[90],"WEB",{"url":92,"sources":93,"tags":94},"https://www.suse.com/security/cve/CVE-2026-2340",[43],[90],{"url":96,"sources":97,"tags":98},"https://www.suse.com/security/cve/CVE-2026-3012",[43],[90],{"url":100,"sources":101,"tags":102},"https://www.suse.com/security/cve/CVE-2026-3238",[43],[90],{"url":104,"sources":105,"tags":106},"https://www.suse.com/security/cve/CVE-2026-4408",[43],[90],{"url":108,"sources":109,"tags":110},"https://www.suse.com/security/cve/CVE-2026-4480",[43],[90],[],[],[],[115],{"ecosystem":116,"name":117,"vendor":118,"product":119,"cpe_part":9,"purl_type":120,"purl_namespace":118,"purl_name":119,"source":9,"versions":121},"openSUSE","samba","opensuse","samba&distro=openSUSE Leap 16.0","rpm",[122],{"version":123,"is_range":124,"range_type":125,"version_start":9,"version_start_type":9,"version_end":126,"version_end_type":127,"fixed_in":9},"lt4_22_9+git_506_22c03ce0781_160000_1_1",true,"ecosystem","4.22.9+git.506.22c03ce0781-160000.1.1","excluding"]