Описание
A flaw was found in Samba’s vfs_worm module. The module is intended to provide write-once, read-many (WORM) protections by preventing modification of files after a configurable grace period. Due to insufficient validation during rename operations, an authenticated user with write access to a share could overwrite a protected file by renaming a newly created file over the existing WORM-protected file.
Отчет
This vulnerability is rated Moderate severity because exploitation requires authenticated write access to a Samba share already configured to permit file creation and modification. The flaw affects the vfs_worm module, which provides additional immutability protections for files after a configurable grace period. Due to improper handling of rename operations, a user with existing write permissions could overwrite files that should have become immutable under the WORM policy. The vulnerability does not bypass underlying filesystem access controls or grant additional privileges beyond those already assigned to the authenticated user. However, because the primary purpose of the vfs_worm module is to protect file integrity, the ability to modify protected files results in a high integrity impact.
Меры по смягчению последствий
Administrators can mitigate this issue by:
Setting read-only permissions on protected files at the underlying filesystem level will prevent modifications.
Configuring worm:grace_period = 0 (zero or less) in smb.conf will eliminate the writable grace period (will eliminate the window in which the rename can happen), understanding that this may impact workflows requiring multi-step file creation.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | samba | Out of support scope | ||
| Red Hat Enterprise Linux 6 | samba4 | Out of support scope | ||
| Red Hat Enterprise Linux 7 | samba | Will not fix | ||
| Red Hat Enterprise Linux 10 | samba | Fixed | RHSA-2026:22963 | 03.06.2026 |
| Red Hat Enterprise Linux 10.0 Extended Update Support | samba | Fixed | RHSA-2026:28055 | 23.06.2026 |
| Red Hat Enterprise Linux 8 | samba | Fixed | RHSA-2026:22644 | 03.06.2026 |
| Red Hat Enterprise Linux 8 | samba | Fixed | RHSA-2026:22644 | 03.06.2026 |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | samba | Fixed | RHSA-2026:28057 | 23.06.2026 |
| Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On | samba | Fixed | RHSA-2026:28057 | 23.06.2026 |
| Red Hat Enterprise Linux 8.8 Telecommunications Update Service | samba | Fixed | RHSA-2026:28056 | 23.06.2026 |
Показывать по
Дополнительная информация
Статус:
6.5 Medium
CVSS3
Связанные уязвимости
A flaw was found in Samba’s vfs_worm module. The module is intended to provide write-once, read-many (WORM) protections by preventing modification of files after a configurable grace period. Due to insufficient validation during rename operations, an authenticated user with write access to a share could overwrite a protected file by renaming a newly created file over the existing WORM-protected file.
A flaw was found in Samba’s vfs_worm module. The module is intended to provide write-once, read-many (WORM) protections by preventing modification of files after a configurable grace period. Due to insufficient validation during rename operations, an authenticated user with write access to a share could overwrite a protected file by renaming a newly created file over the existing WORM-protected file.
A flaw was found in Samba\u2019s vfs_worm module. The module is intend ...
A flaw was found in Samba’s vfs_worm module. The module is intended to provide write-once, read-many (WORM) protections by preventing modification of files after a configurable grace period. Due to insufficient validation during rename operations, an authenticated user with write access to a share could overwrite a protected file by renaming a newly created file over the existing WORM-protected file.
Уязвимость модуля vfs_worm программного обеспечения Samba, позволяющая нарушителю изменить произвольные файлы
6.5 Medium
CVSS3