Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-58218

Опубликовано: 28 июл. 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 5.3

Описание

DNS signing DoS via TKEY name cache exhaustion. An unauthenticated user can repeatedly register names TKEY names, which floods a cache causing legitimate TKEYs to be expunged. This can practically block the use DNS TSIG signing.

РелизСтатусПримечание
devel

needed

esm-infra-legacy/trusty

needs-triage

esm-infra-legacy/xenial

needs-triage

esm-infra/bionic

needs-triage

esm-infra/focal

needs-triage

jammy

released

2:4.15.13+dfsg-0ubuntu1.13
noble

released

2:4.19.5+dfsg-4ubuntu9.7
resolute

released

2:4.23.6+dfsg-1ubuntu2.2
upstream

released

4.24.5,4.23.10,4.22.11

Показывать по

EPSS

Процентиль: 62%
0.011
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
redhat
7 дней назад

A flaw was found in Samba's internal DNS server where unauthenticated TKEY registration requests were added to the TKEY name cache before being rejected. A remote, unauthenticated attacker can exploit this behavior by sending a large number of TKEY requests with arbitrary names, exhausting the cache and evicting legitimate TKEY entries. This can prevent legitimate TSIG authentication for signed DNS queries, resulting in a denial of service.

CVSS3: 5.3
nvd
5 дней назад

A flaw was found in Samba's internal DNS server where unauthenticated TKEY registration requests were added to the TKEY name cache before being rejected. A remote, unauthenticated attacker can exploit this behavior by sending a large number of TKEY requests with arbitrary names, exhausting the cache and evicting legitimate TKEY entries. This can prevent legitimate TSIG authentication for signed DNS queries, resulting in a denial of service.

CVSS3: 5.3
debian
5 дней назад

A flaw was found in Samba's internal DNS server where unauthenticated ...

CVSS3: 5.3
github
5 дней назад

A flaw was found in Samba's internal DNS server where unauthenticated TKEY registration requests were added to the TKEY name cache before being rejected. A remote, unauthenticated attacker can exploit this behavior by sending a large number of TKEY requests with arbitrary names, exhausting the cache and evicting legitimate TKEY entries. This can prevent legitimate TSIG authentication for signed DNS queries, resulting in a denial of service.

suse-cvrf
6 дней назад

Security update for samba

EPSS

Процентиль: 62%
0.011
Низкий

5.3 Medium

CVSS3