Описание
Security update for samba
This update for samba fixes the following issues
- CVE-2026-6949: TSIG packet with crafted name compression can crash internal DNS server (bsc#1271672).
- CVE-2026-15779:
pam_winbindmodule withmkhomedirset allowschownof critical system paths without validation (bsc#1271469). - CVE-2026-58216: 6-byte heap OOB read in packet parser of the
kpasswdservice (bsc#1271674). - CVE-2026-58218: DNS TKEY negotiation stores unauthenticated GSS contexts in a fixed FIFO before authentication completes (bsc#1271675).
- CVE-2026-58221: authenticated LDAP access to internal LDB special DNs permits domain takeover (bsc#1271676).
- CVE-2026-58222: LDAP Compare filter injection and trusted-request confusion disclose protected attributes (bsc#1271677).
- CVE-2026-58224: heap OOB read due to unchecked packet length fields in CTDB (bsc#1271673).
Список пакетов
SUSE Linux Enterprise High Availability Extension 15 SP5
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS
SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS
SUSE Linux Enterprise Micro 5.5
SUSE Linux Enterprise Server 15 SP5-LTSS
SUSE Linux Enterprise Server for SAP Applications 15 SP5
Ссылки
- Link for SUSE-SU-2026:3365-1
- E-Mail link for SUSE-SU-2026:3365-1
- SUSE Security Ratings
- SUSE Bug 1271469
- SUSE Bug 1271672
- SUSE Bug 1271673
- SUSE Bug 1271674
- SUSE Bug 1271675
- SUSE Bug 1271676
- SUSE Bug 1271677
- SUSE CVE CVE-2026-15779 page
- SUSE CVE CVE-2026-58216 page
- SUSE CVE CVE-2026-58218 page
- SUSE CVE CVE-2026-58221 page
- SUSE CVE CVE-2026-58222 page
- SUSE CVE CVE-2026-58224 page
- SUSE CVE CVE-2026-6949 page
Описание
A flaw was found in samba's pam_winbind. When mkhomedir is enabled, pam_winbind chowns the target account's home directory without validating the path is not a critical system directory such as /. On affected systems, accounts with / as their home directory (a common default for system accounts) can have this triggered not only by root, but by a non-root user holding a narrow sudo delegation to run commands as that account, causing ownership of / to change and resulting in severe denial of service (SSH, sudo, and package-manager failures). The change does not grant write access to / (which ships with restrictive 0555 permissions on RHEL), so the impact is availability loss rather than further privilege escalation.
Затронутые продукты
Ссылки
- CVE-2026-15779
- SUSE Bug 1271469
Описание
unknown
Затронутые продукты
Ссылки
- CVE-2026-58216
- SUSE Bug 1271674
Описание
unknown
Затронутые продукты
Ссылки
- CVE-2026-58218
- SUSE Bug 1271675
Описание
unknown
Затронутые продукты
Ссылки
- CVE-2026-58221
- SUSE Bug 1271676
Описание
unknown
Затронутые продукты
Ссылки
- CVE-2026-58222
- SUSE Bug 1271677
Описание
unknown
Затронутые продукты
Ссылки
- CVE-2026-58224
- SUSE Bug 1271673
Описание
unknown
Затронутые продукты
Ссылки
- CVE-2026-6949
- SUSE Bug 1271672
- SUSE Bug 1271675