Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

fstec логотип

BDU:2026-07423

Опубликовано: 26 мая 2026
Источник: fstec
CVSS3: 7.5
CVSS2: 7.8
EPSS Низкий

Описание

Уязвимость WINS-сервера программного обеспечения Samba связана с разыменованием указателей. Эксплуатация уязвимости может позволить нарушителю, действующему удаленно, вызвать отказ в обслуживании

Вендор

Сообщество свободного программного обеспечения
Amazon.com Inc.
Canonical Ltd.
Samba Team

Наименование ПО

Debian GNU/Linux
Amazon Linux 2
Ubuntu
Samba

Версия ПО

12 (Debian GNU/Linux)
- (Amazon Linux 2)
24.04 LTS (Ubuntu)
13 (Debian GNU/Linux)
25.10 (Ubuntu)
26.04 LTS (Ubuntu)
от 4.0 до 4.22.10 (Samba)
от 4.0 до 4.23.8 (Samba)
от 4.0 до 4.24.3 (Samba)

Тип ПО

Операционная система
Сетевое программное средство

Операционные системы и аппаратные платформы

Сообщество свободного программного обеспечения Debian GNU/Linux 12
Amazon.com Inc. Amazon Linux 2 -
Canonical Ltd. Ubuntu 24.04 LTS
Сообщество свободного программного обеспечения Debian GNU/Linux 13
Canonical Ltd. Ubuntu 25.10
Canonical Ltd. Ubuntu 26.04 LTS

Уровень опасности уязвимости

Высокий уровень опасности (базовая оценка CVSS 2.0 составляет 7,8)
Высокий уровень опасности (базовая оценка CVSS 3.1 составляет 7,5)

Возможные меры по устранению уязвимости

Использование рекомендаций:
Для Samba:
https://lists.debian.org/debian-security-announce/2026/msg00208.html
Для Amazon Linux:
https://alas.aws.amazon.com/AL2/ALAS2-2026-3238.html
Для Debian GNU/Linux:
https://lists.debian.org/debian-security-announce/2026/msg00208.html
Для Ubuntu:
https://ubuntu.com/security/notices/USN-8306-1
Компенсирующие меры:
- удаление параметра wins support = yes из конфигурации smb.conf для затронутых сетевых сегментов, не использующих службы WINS

Статус уязвимости

Подтверждена производителем

Наличие эксплойта

Данные уточняются

Информация об устранении

Уязвимость устранена

Идентификаторы других систем описаний уязвимостей

EPSS

Процентиль: 84%
0.02669
Низкий

7.5 High

CVSS3

7.8 High

CVSS2

Связанные уязвимости

CVSS3: 7.5
ubuntu
2 месяца назад

A flaw was found in Samba’s WINS server component when running as an Active Directory Domain Controller. The WINS protocol handlers for certain request types did not properly validate incoming packets, allowing an unauthenticated remote attacker to trigger a NULL pointer dereference and crash the WINS service using specially crafted UDP packets.

CVSS3: 7.5
redhat
2 месяца назад

A flaw was found in Samba’s WINS server component when running as an Active Directory Domain Controller. The WINS protocol handlers for certain request types did not properly validate incoming packets, allowing an unauthenticated remote attacker to trigger a NULL pointer dereference and crash the WINS service using specially crafted UDP packets.

CVSS3: 7.5
nvd
2 месяца назад

A flaw was found in Samba’s WINS server component when running as an Active Directory Domain Controller. The WINS protocol handlers for certain request types did not properly validate incoming packets, allowing an unauthenticated remote attacker to trigger a NULL pointer dereference and crash the WINS service using specially crafted UDP packets.

CVSS3: 7.5
debian
2 месяца назад

A flaw was found in Samba\u2019s WINS server component when running as ...

CVSS3: 7.5
github
2 месяца назад

A flaw was found in Samba’s WINS server component when running as an Active Directory Domain Controller. The WINS protocol handlers for certain request types did not properly validate incoming packets, allowing an unauthenticated remote attacker to trigger a NULL pointer dereference and crash the WINS service using specially crafted UDP packets.

EPSS

Процентиль: 84%
0.02669
Низкий

7.5 High

CVSS3

7.8 High

CVSS2