Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-4480

Опубликовано: 26 мая 2026
Источник: redhat
CVSS3: 9

Описание

A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the "print command" setting via the "%J" substitution character without escaping shell meta characters. A remote attacker could exploit this vulnerability by sending a specially crafted print job description that contains unescaped shell characters. This could lead to remote code execution on the affected system.

Отчет

The issue affects the Samba printing subsystem. Red Hat has classified this issue as Important severity rather than Critical. Print servers configured with "printing = cups" or "printing = iprint", and print servers that do not have the "%J" substitution character in the "print command" setting are not affected. By default, Red Hat Enterprise Linux ships with Samba configured to use CUPS-based printing printing = cups. Hence, although the vulnerable code is present, it is not exploitable in default RHEL configurations. Because exploitation depends on non-default Samba printing configurations and requires use of the %J substitution parameter within print command, the attack complexity is considered High (AC:H), reducing the likelihood of exploitation in standard deployments.

Меры по смягчению последствий

Remove "%J" from the "print command" in smb.conf entry.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6sambaOut of support scope
Red Hat Enterprise Linux 6samba4Out of support scope
Red Hat OpenShift Container Platform 4rhcosNot affected
Red Hat Enterprise Linux 10sambaFixedRHSA-2026:2296303.06.2026
Red Hat Enterprise Linux 10.0 Extended Update SupportsambaFixedRHSA-2026:2805523.06.2026
Red Hat Enterprise Linux 7 Extended Lifecycle SupportsambaFixedRHSA-2026:2813223.06.2026
Red Hat Enterprise Linux 7 Extended Lifecycle SupportsambaFixedRHSA-2026:2813223.06.2026
Red Hat Enterprise Linux 8sambaFixedRHSA-2026:2264403.06.2026
Red Hat Enterprise Linux 8sambaFixedRHSA-2026:2264403.06.2026
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportsambaFixedRHSA-2026:2805823.06.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-78
https://bugzilla.redhat.com/show_bug.cgi?id=2452232samba: Samba: Remote Code Execution in printing subsystem via unescaped job description

9 Critical

CVSS3

Связанные уязвимости

CVSS3: 9
ubuntu
2 месяца назад

A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the "print command" setting via the "%J" substitution character without escaping shell meta characters. A remote attacker could exploit this vulnerability by sending a specially crafted print job description that contains unescaped shell characters. This could lead to remote code execution on the affected system.

CVSS3: 9
nvd
2 месяца назад

A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the "print command" setting via the "%J" substitution character without escaping shell meta characters. A remote attacker could exploit this vulnerability by sending a specially crafted print job description that contains unescaped shell characters. This could lead to remote code execution on the affected system.

CVSS3: 9
debian
2 месяца назад

A flaw was found in the Samba printing subsystem. Samba passes the cli ...

CVSS3: 8.5
github
2 месяца назад

A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the "print command" setting via the "%J" substitution character without escaping shell meta characters. A remote attacker could exploit this vulnerability by sending a specially crafted print job description that contains unescaped shell characters. This could lead to remote code execution on the affected system.

CVSS3: 10
fstec
2 месяца назад

Уязвимость подсистемы печати (printing subsystem) программ сетевого взаимодействия Samba, позволяющая нарушителю выполнить произвольный код

9 Critical

CVSS3