SUSE-SU-2026:22977-1
Vulnerability Summary
Timeline
Description
Security update for samba This update for samba fixes the following issues: - CVE-2026-6949: TSIG packet with crafted name compression can crash internal DNS server (bsc#1271672). - CVE-2026-15779: `pam_winbind` module with `mkhomedir` set allows `chown` of critical system paths without validation (bsc#1271469). - CVE-2026-58216: 6-byte heap OOB read in packet parser of the `kpasswd` service (bsc#1271674). - CVE-2026-58218: DNS TKEY negotiation stores unauthenticated GSS contexts in a fixed FIFO before authentication completes (bsc#1271675). - CVE-2026-58221: authenticated LDAP access to internal LDB special DNs permits domain takeover (bsc#1271676). - CVE-2026-58222: LDAP Compare filter injection and trusted-request confusion disclose protected attributes (bsc#1271677). - CVE-2026-58224: heap OOB read due to unchecked packet length fields in CTDB (bsc#1271673).
Affected Systems
- suse•samba&distro=SUSE Linux Micro 6.2
< 4.22.9+git.538.af6cb4fb2e-160000.1.1
References (15)
- https://www.suse.com/support/update/announcement/2026/suse-su-202622977-1/
- https://bugzilla.suse.com/1271469
- https://bugzilla.suse.com/1271672
- https://bugzilla.suse.com/1271673
- https://bugzilla.suse.com/1271674
- https://bugzilla.suse.com/1271675
- https://bugzilla.suse.com/1271676
- https://bugzilla.suse.com/1271677
- https://www.suse.com/security/cve/CVE-2026-15779
- https://www.suse.com/security/cve/CVE-2026-58216
- https://www.suse.com/security/cve/CVE-2026-58218
- https://www.suse.com/security/cve/CVE-2026-58221
- https://www.suse.com/security/cve/CVE-2026-58222
- https://www.suse.com/security/cve/CVE-2026-58224
- https://www.suse.com/security/cve/CVE-2026-6949