Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-1933

Опубликовано: 27 мая 2026
Источник: redhat
CVSS3: 7.1
EPSS Низкий

Описание

A flaw was found in Samba’s handling of NTFS-style reparse points on shares configured with read only = yes. Due to missing SMB-layer access checks, authenticated users with underlying filesystem write permissions may create or delete reparse point metadata through SMB operations even on read-only exports. This could allow modification of SMB-visible file behavior, including converting files into symbolic links or other reparse point types.

Отчет

This vulnerability is rated Important severity by Red Hat Product Security, because authenticated users with filesystem-level write permissions may bypass Samba’s SMB-layer read-only protections for reparse point operations. The flaw affects shares configured with "read only = yes", where Samba failed to properly enforce access checks when setting or deleting reparse point metadata. An attacker with existing write permissions on the underlying filesystem may manipulate SMB reparse point metadata to alter how files are presented to SMB clients, including converting files into symbolic links. The vulnerability does not bypass underlying filesystem access controls or grant additional operating system privileges. However, successful exploitation may significantly disrupt file access for users of the affected share, including making large portions of a shared filesystem unavailable through widespread reparse point modification. Because the attack requires authenticated access and existing filesystem write permissions, Privileges Required are assessed as Low (PR:L).

This vulnerability affects Samba versions beginning with the introduction of NTFS-style reparse point support in Samba 4.21.

Меры по смягчению последствий

Administrators can mitigate this issue by ensuring users who access a read only = yes Samba share do not have filesystem-level write permission to the exported files. A server administrator may also monitor and remove unintended "user.SmbReparse" xattr (extended attributes) and the associated FILE_ATTRIBUTE_REPARSE_POINT "user.DosAttrib" bit metadata if exploitation is suspected.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6sambaOut of support scope
Red Hat Enterprise Linux 6samba4Out of support scope
Red Hat Enterprise Linux 7sambaWill not fix
Red Hat Enterprise Linux 10sambaFixedRHSA-2026:2296303.06.2026
Red Hat Enterprise Linux 10.0 Extended Update SupportsambaFixedRHSA-2026:2805523.06.2026
Red Hat Enterprise Linux 8sambaFixedRHSA-2026:2264403.06.2026
Red Hat Enterprise Linux 8sambaFixedRHSA-2026:2264403.06.2026
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportsambaFixedRHSA-2026:2805723.06.2026
Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-OnsambaFixedRHSA-2026:2805723.06.2026
Red Hat Enterprise Linux 8.8 Telecommunications Update ServicesambaFixedRHSA-2026:2805623.06.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-284
https://bugzilla.redhat.com/show_bug.cgi?id=2447317samba: Missing access check on reparse point operations

EPSS

Процентиль: 55%
0.00862
Низкий

7.1 High

CVSS3

Связанные уязвимости

CVSS3: 7.1
ubuntu
2 месяца назад

A flaw was found in Samba’s handling of NTFS-style reparse points on shares configured with read only = yes. Due to missing SMB-layer access checks, authenticated users with underlying filesystem write permissions may create or delete reparse point metadata through SMB operations even on read-only exports. This could allow modification of SMB-visible file behavior, including converting files into symbolic links or other reparse point types.

CVSS3: 7.1
nvd
2 месяца назад

A flaw was found in Samba’s handling of NTFS-style reparse points on shares configured with read only = yes. Due to missing SMB-layer access checks, authenticated users with underlying filesystem write permissions may create or delete reparse point metadata through SMB operations even on read-only exports. This could allow modification of SMB-visible file behavior, including converting files into symbolic links or other reparse point types.

CVSS3: 7.1
debian
2 месяца назад

A flaw was found in Samba\u2019s handling of NTFS-style reparse points ...

CVSS3: 7.1
github
2 месяца назад

A flaw was found in Samba’s handling of NTFS-style reparse points on shares configured with read only = yes. Due to missing SMB-layer access checks, authenticated users with underlying filesystem write permissions may create or delete reparse point metadata through SMB operations even on read-only exports. This could allow modification of SMB-visible file behavior, including converting files into symbolic links or other reparse point types.

CVSS3: 7.1
fstec
2 месяца назад

Уязвимость механизма NTFS reparse points программного обеспечения Samba, позволяющая нарушителю изменить произвольные файлы

EPSS

Процентиль: 55%
0.00862
Низкий

7.1 High

CVSS3