Описание
A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the "print command" setting via the "%J" substitution character without escaping shell meta characters. A remote attacker could exploit this vulnerability by sending a specially crafted print job description that contains unescaped shell characters. This could lead to remote code execution on the affected system.
Отчет
The issue affects the Samba printing subsystem. Red Hat has classified this issue as Important severity rather than Critical.
Print servers configured with "printing = cups" or "printing = iprint", and print servers that do not have the "%J" substitution character in the "print command" setting are not affected.
By default, Red Hat Enterprise Linux ships with Samba configured to use CUPS-based printing printing = cups. Hence, although the vulnerable code is present, it is not exploitable in default RHEL configurations.
Because exploitation depends on non-default Samba printing configurations and requires use of the %J substitution parameter within print command, the attack complexity is considered High (AC:H), reducing the likelihood of exploitation in standard deployments.
Меры по смягчению последствий
Remove "%J" from the "print command" in smb.conf entry.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | samba | Out of support scope | ||
| Red Hat Enterprise Linux 6 | samba4 | Out of support scope | ||
| Red Hat OpenShift Container Platform 4 | rhcos | Not affected | ||
| Red Hat Enterprise Linux 10 | samba | Fixed | RHSA-2026:22963 | 03.06.2026 |
| Red Hat Enterprise Linux 10.0 Extended Update Support | samba | Fixed | RHSA-2026:28055 | 23.06.2026 |
| Red Hat Enterprise Linux 7 Extended Lifecycle Support | samba | Fixed | RHSA-2026:28132 | 23.06.2026 |
| Red Hat Enterprise Linux 7 Extended Lifecycle Support | samba | Fixed | RHSA-2026:28132 | 23.06.2026 |
| Red Hat Enterprise Linux 8 | samba | Fixed | RHSA-2026:22644 | 03.06.2026 |
| Red Hat Enterprise Linux 8 | samba | Fixed | RHSA-2026:22644 | 03.06.2026 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | samba | Fixed | RHSA-2026:28058 | 23.06.2026 |
Показывать по
Дополнительная информация
Статус:
9 Critical
CVSS3
Связанные уязвимости
A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the "print command" setting via the "%J" substitution character without escaping shell meta characters. A remote attacker could exploit this vulnerability by sending a specially crafted print job description that contains unescaped shell characters. This could lead to remote code execution on the affected system.
A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the "print command" setting via the "%J" substitution character without escaping shell meta characters. A remote attacker could exploit this vulnerability by sending a specially crafted print job description that contains unescaped shell characters. This could lead to remote code execution on the affected system.
A flaw was found in the Samba printing subsystem. Samba passes the cli ...
A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the "print command" setting via the "%J" substitution character without escaping shell meta characters. A remote attacker could exploit this vulnerability by sending a specially crafted print job description that contains unescaped shell characters. This could lead to remote code execution on the affected system.
Уязвимость подсистемы печати (printing subsystem) программ сетевого взаимодействия Samba, позволяющая нарушителю выполнить произвольный код
9 Critical
CVSS3