Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-58218

Опубликовано: 30 июл. 2026
Источник: nvd
CVSS3: 5.3
EPSS Низкий

Описание

A flaw was found in Samba's internal DNS server where unauthenticated TKEY registration requests were added to the TKEY name cache before being rejected. A remote, unauthenticated attacker can exploit this behavior by sending a large number of TKEY requests with arbitrary names, exhausting the cache and evicting legitimate TKEY entries. This can prevent legitimate TSIG authentication for signed DNS queries, resulting in a denial of service.

EPSS

Процентиль: 62%
0.011
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-410

Связанные уязвимости

CVSS3: 5.3
ubuntu
7 дней назад

DNS signing DoS via TKEY name cache exhaustion. An unauthenticated user can repeatedly register names TKEY names, which floods a cache causing legitimate TKEYs to be expunged. This can practically block the use DNS TSIG signing.

CVSS3: 5.3
redhat
7 дней назад

A flaw was found in Samba's internal DNS server where unauthenticated TKEY registration requests were added to the TKEY name cache before being rejected. A remote, unauthenticated attacker can exploit this behavior by sending a large number of TKEY requests with arbitrary names, exhausting the cache and evicting legitimate TKEY entries. This can prevent legitimate TSIG authentication for signed DNS queries, resulting in a denial of service.

CVSS3: 5.3
debian
5 дней назад

A flaw was found in Samba's internal DNS server where unauthenticated ...

CVSS3: 5.3
github
5 дней назад

A flaw was found in Samba's internal DNS server where unauthenticated TKEY registration requests were added to the TKEY name cache before being rejected. A remote, unauthenticated attacker can exploit this behavior by sending a large number of TKEY requests with arbitrary names, exhausting the cache and evicting legitimate TKEY entries. This can prevent legitimate TSIG authentication for signed DNS queries, resulting in a denial of service.

suse-cvrf
6 дней назад

Security update for samba

EPSS

Процентиль: 62%
0.011
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-410