Описание
A flaw was found in Samba’s handling of NTFS-style reparse points on shares configured with read only = yes. Due to missing SMB-layer access checks, authenticated users with underlying filesystem write permissions may create or delete reparse point metadata through SMB operations even on read-only exports. This could allow modification of SMB-visible file behavior, including converting files into symbolic links or other reparse point types.
Отчет
This vulnerability is rated Important severity by Red Hat Product Security, because authenticated users with filesystem-level write permissions may bypass Samba’s SMB-layer read-only protections for reparse point operations. The flaw affects shares configured with "read only = yes", where Samba failed to properly enforce access checks when setting or deleting reparse point metadata. An attacker with existing write permissions on the underlying filesystem may manipulate SMB reparse point metadata to alter how files are presented to SMB clients, including converting files into symbolic links. The vulnerability does not bypass underlying filesystem access controls or grant additional operating system privileges. However, successful exploitation may significantly disrupt file access for users of the affected share, including making large portions of a shared filesystem unavailable through widespread reparse point modification. Because the attack requires authenticated access and existing filesystem write permissions, Privileges Required are assessed as Low (PR:L).
Меры по смягчению последствий
Administrators can mitigate this issue by ensuring users who access a read only = yes Samba share do not have filesystem-level write permission to the exported files. A server administrator may also monitor and remove unintended "user.SmbReparse" xattr (extended attributes) and the associated FILE_ATTRIBUTE_REPARSE_POINT "user.DosAttrib" bit metadata if exploitation is suspected.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | samba | Out of support scope | ||
| Red Hat Enterprise Linux 6 | samba4 | Out of support scope | ||
| Red Hat Enterprise Linux 7 | samba | Will not fix | ||
| Red Hat Enterprise Linux 10 | samba | Fixed | RHSA-2026:22963 | 03.06.2026 |
| Red Hat Enterprise Linux 10.0 Extended Update Support | samba | Fixed | RHSA-2026:28055 | 23.06.2026 |
| Red Hat Enterprise Linux 8 | samba | Fixed | RHSA-2026:22644 | 03.06.2026 |
| Red Hat Enterprise Linux 8 | samba | Fixed | RHSA-2026:22644 | 03.06.2026 |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | samba | Fixed | RHSA-2026:28057 | 23.06.2026 |
| Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On | samba | Fixed | RHSA-2026:28057 | 23.06.2026 |
| Red Hat Enterprise Linux 8.8 Telecommunications Update Service | samba | Fixed | RHSA-2026:28056 | 23.06.2026 |
Показывать по
Дополнительная информация
Статус:
EPSS
7.1 High
CVSS3
Связанные уязвимости
A flaw was found in Samba’s handling of NTFS-style reparse points on shares configured with read only = yes. Due to missing SMB-layer access checks, authenticated users with underlying filesystem write permissions may create or delete reparse point metadata through SMB operations even on read-only exports. This could allow modification of SMB-visible file behavior, including converting files into symbolic links or other reparse point types.
A flaw was found in Samba’s handling of NTFS-style reparse points on shares configured with read only = yes. Due to missing SMB-layer access checks, authenticated users with underlying filesystem write permissions may create or delete reparse point metadata through SMB operations even on read-only exports. This could allow modification of SMB-visible file behavior, including converting files into symbolic links or other reparse point types.
A flaw was found in Samba\u2019s handling of NTFS-style reparse points ...
A flaw was found in Samba’s handling of NTFS-style reparse points on shares configured with read only = yes. Due to missing SMB-layer access checks, authenticated users with underlying filesystem write permissions may create or delete reparse point metadata through SMB operations even on read-only exports. This could allow modification of SMB-visible file behavior, including converting files into symbolic links or other reparse point types.
Уязвимость механизма NTFS reparse points программного обеспечения Samba, позволяющая нарушителю изменить произвольные файлы
EPSS
7.1 High
CVSS3