Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-2340

Опубликовано: 27 мая 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 6.5

Описание

A flaw was found in Samba’s vfs_worm module. The module is intended to provide write-once, read-many (WORM) protections by preventing modification of files after a configurable grace period. Due to insufficient validation during rename operations, an authenticated user with write access to a share could overwrite a protected file by renaming a newly created file over the existing WORM-protected file.

РелизСтатусПримечание
devel

not-affected

2:4.23.6+dfsg-1ubuntu3
esm-infra-legacy/trusty

not-affected

code not present
esm-infra-legacy/xenial

not-affected

code not present
esm-infra/bionic

not-affected

code not present
esm-infra/focal

not-affected

code not present
esm-infra/xenial

ignored

end of ESM support, was needs-triage
jammy

released

2:4.15.13+dfsg-0ubuntu1.12
noble

released

2:4.19.5+dfsg-4ubuntu9.6
questing

released

2:4.22.3+dfsg-4ubuntu2.4
resolute

released

2:4.23.6+dfsg-1ubuntu2.1

Показывать по

EPSS

Процентиль: 57%
0.00939
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
redhat
2 месяца назад

A flaw was found in Samba’s vfs_worm module. The module is intended to provide write-once, read-many (WORM) protections by preventing modification of files after a configurable grace period. Due to insufficient validation during rename operations, an authenticated user with write access to a share could overwrite a protected file by renaming a newly created file over the existing WORM-protected file.

CVSS3: 6.5
nvd
2 месяца назад

A flaw was found in Samba’s vfs_worm module. The module is intended to provide write-once, read-many (WORM) protections by preventing modification of files after a configurable grace period. Due to insufficient validation during rename operations, an authenticated user with write access to a share could overwrite a protected file by renaming a newly created file over the existing WORM-protected file.

CVSS3: 6.5
debian
2 месяца назад

A flaw was found in Samba\u2019s vfs_worm module. The module is intend ...

CVSS3: 6.5
github
2 месяца назад

A flaw was found in Samba’s vfs_worm module. The module is intended to provide write-once, read-many (WORM) protections by preventing modification of files after a configurable grace period. Due to insufficient validation during rename operations, an authenticated user with write access to a share could overwrite a protected file by renaming a newly created file over the existing WORM-protected file.

CVSS3: 7.3
fstec
2 месяца назад

Уязвимость модуля vfs_worm программного обеспечения Samba, позволяющая нарушителю изменить произвольные файлы

EPSS

Процентиль: 57%
0.00939
Низкий

6.5 Medium

CVSS3