SUSE-SU-2026:22977-1

Advisory lineage Upstream: 7 Downstream: 0
Published: 29 Jul 2026, 04:55
Last modified:04 Aug 2026, 18:23

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

29 Jul 2026, 04:55
Published
Vulnerability first disclosed
04 Aug 2026, 18:23
Last Modified
Vulnerability information updated

Description

Security update for samba This update for samba fixes the following issues: - CVE-2026-6949: TSIG packet with crafted name compression can crash internal DNS server (bsc#1271672). - CVE-2026-15779: `pam_winbind` module with `mkhomedir` set allows `chown` of critical system paths without validation (bsc#1271469). - CVE-2026-58216: 6-byte heap OOB read in packet parser of the `kpasswd` service (bsc#1271674). - CVE-2026-58218: DNS TKEY negotiation stores unauthenticated GSS contexts in a fixed FIFO before authentication completes (bsc#1271675). - CVE-2026-58221: authenticated LDAP access to internal LDB special DNs permits domain takeover (bsc#1271676). - CVE-2026-58222: LDAP Compare filter injection and trusted-request confusion disclose protected attributes (bsc#1271677). - CVE-2026-58224: heap OOB read due to unchecked packet length fields in CTDB (bsc#1271673).

Affected Systems

  • susesamba&distro=SUSE Linux Micro 6.2

    < 4.22.9+git.538.af6cb4fb2e-160000.1.1

References (15)