Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-2340

Опубликовано: 27 мая 2026
Источник: redhat
CVSS3: 6.5

Описание

A flaw was found in Samba’s vfs_worm module. The module is intended to provide write-once, read-many (WORM) protections by preventing modification of files after a configurable grace period. Due to insufficient validation during rename operations, an authenticated user with write access to a share could overwrite a protected file by renaming a newly created file over the existing WORM-protected file.

Отчет

This vulnerability is rated Moderate severity because exploitation requires authenticated write access to a Samba share already configured to permit file creation and modification. The flaw affects the vfs_worm module, which provides additional immutability protections for files after a configurable grace period. Due to improper handling of rename operations, a user with existing write permissions could overwrite files that should have become immutable under the WORM policy. The vulnerability does not bypass underlying filesystem access controls or grant additional privileges beyond those already assigned to the authenticated user. However, because the primary purpose of the vfs_worm module is to protect file integrity, the ability to modify protected files results in a high integrity impact.

Меры по смягчению последствий

Administrators can mitigate this issue by: Setting read-only permissions on protected files at the underlying filesystem level will prevent modifications. Configuring worm:grace_period = 0 (zero or less) in smb.conf will eliminate the writable grace period (will eliminate the window in which the rename can happen), understanding that this may impact workflows requiring multi-step file creation.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6sambaOut of support scope
Red Hat Enterprise Linux 6samba4Out of support scope
Red Hat Enterprise Linux 7sambaWill not fix
Red Hat Enterprise Linux 10sambaFixedRHSA-2026:2296303.06.2026
Red Hat Enterprise Linux 10.0 Extended Update SupportsambaFixedRHSA-2026:2805523.06.2026
Red Hat Enterprise Linux 8sambaFixedRHSA-2026:2264403.06.2026
Red Hat Enterprise Linux 8sambaFixedRHSA-2026:2264403.06.2026
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportsambaFixedRHSA-2026:2805723.06.2026
Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-OnsambaFixedRHSA-2026:2805723.06.2026
Red Hat Enterprise Linux 8.8 Telecommunications Update ServicesambaFixedRHSA-2026:2805623.06.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-280
https://bugzilla.redhat.com/show_bug.cgi?id=2447318samba: vfs_worm does not block directory modification

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
2 месяца назад

A flaw was found in Samba’s vfs_worm module. The module is intended to provide write-once, read-many (WORM) protections by preventing modification of files after a configurable grace period. Due to insufficient validation during rename operations, an authenticated user with write access to a share could overwrite a protected file by renaming a newly created file over the existing WORM-protected file.

CVSS3: 6.5
nvd
2 месяца назад

A flaw was found in Samba’s vfs_worm module. The module is intended to provide write-once, read-many (WORM) protections by preventing modification of files after a configurable grace period. Due to insufficient validation during rename operations, an authenticated user with write access to a share could overwrite a protected file by renaming a newly created file over the existing WORM-protected file.

CVSS3: 6.5
debian
2 месяца назад

A flaw was found in Samba\u2019s vfs_worm module. The module is intend ...

CVSS3: 6.5
github
2 месяца назад

A flaw was found in Samba’s vfs_worm module. The module is intended to provide write-once, read-many (WORM) protections by preventing modification of files after a configurable grace period. Due to insufficient validation during rename operations, an authenticated user with write access to a share could overwrite a protected file by renaming a newly created file over the existing WORM-protected file.

CVSS3: 7.3
fstec
2 месяца назад

Уязвимость модуля vfs_worm программного обеспечения Samba, позволяющая нарушителю изменить произвольные файлы

6.5 Medium

CVSS3