Critical: samba security update
Samba is an open-source implementation of the Server Message Block (SMB) protocol and the related Common Internet File System (CIFS) protocol, which allow PC-compatible machines to share files, printers, and various information. Security Fix(es): * samba: Missing access check on reparse point operations (CVE-2026-1933) * samba: vfs_worm does not block directory modification (CVE-2026-2340) * samba: group policy certificate enrollment uses <http://> without validation (CVE-2026-3012) * samba: Samba: Remote Code Execution in printing subsystem via unescaped job description (CVE-2026-4480) * ngtcp2: ngtcp2: Denial of service via stack buffer overflow during QUIC handshake (CVE-2026-40170) * samba: Remote Code Execution in SAMR (CVE-2026-4408) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Samba is an open-source implementation of the Server Message Block (SMB) protocol and the related Common Internet File System (CIFS) protocol, which allow PC-compatible machines to share files, printers, and various information. Security Fix(es): * samba: Missing access check on reparse point operations (CVE-2026-1933) * samba: vfs_worm does not block directory modification (CVE-2026-2340) * samba: group policy certificate enrollment uses <http://> without validation (CVE-2026-3012) * samba: Samba: Remote Code Execution in printing subsystem via unescaped job description (CVE-2026-4480) * ngtcp2: ngtcp2: Denial of service via stack buffer overflow during QUIC handshake (CVE-2026-40170) * samba: Remote Code Execution in SAMR (CVE-2026-4408) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
05 / REFERENCES
Further evidence
- https://access.redhat.com/errata/RHSA-2026:22963
- https://access.redhat.com/security/cve/CVE-2026-1933
- https://access.redhat.com/security/cve/CVE-2026-2340
- https://access.redhat.com/security/cve/CVE-2026-3012
- https://access.redhat.com/security/cve/CVE-2026-40170
- https://access.redhat.com/security/cve/CVE-2026-4408
- https://access.redhat.com/security/cve/CVE-2026-4480
- https://bugzilla.redhat.com/2447317
- https://bugzilla.redhat.com/2447318
- https://bugzilla.redhat.com/2447319
- https://bugzilla.redhat.com/2452232
- https://bugzilla.redhat.com/2459061
- https://bugzilla.redhat.com/2479762
- https://errata.almalinux.org/10/ALSA-2026-22963.html