SUSE-SU-2026:2076-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-20262076-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2076-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/SUSE-SU-2026:2076-1
Upstream
CVE (6)
Related
Published
2026-05-26T12:36:51Z
Modified
2026-05-27T08:16:17Z
Summary
Security update for samba
Details

This update for samba fixes the following issues

Security issues:

  • CVE-2026-1933: Missing access check on reparse point operations (bsc#1261188).
  • CVE-2026-2340: vfs_worm does not block directory modification (bsc#1261158).
  • CVE-2026-3012: group policy certificate enrollment uses http: // without validation (bsc#1261159).
  • CVE-2026-3238: unauthenticated udp packet crashes AD DC nbt server (bsc#1261160).
  • CVE-2026-4408: Remote Code Execution in SAMR (bsc#1261163).
  • CVE-2026-4480: Unauthenticated Remote Code Execution (bsc#1261161).

Non security issue:

  • network:samba:STABLE/samba: 'use-kerberos=desired' broken / Dolphin requires login for Samba shares (bsc#1255755).
  • Generated dynamic profile based on path to special 'printers' share. (bsc#1259441).
  • Fix regression 'use-kerberos=desired' broken doesn't even try to authenticate with kerberos and instead fallsback to NTLM (bsc#1255755).
  • Fix memory leak using cups parsed options and filename allocated when processing end of printing job (bsc#1257200).
  • Fix manpage for 'net offlinejoin requestodj'.
  • Fix 'ctdbd socket' documentation in manpage for smb.conf
  • Fix rpc workers with long living clients from growing server memory keytab and increasing memory used by workers (bsc#1257200).
References

Affected packages