SUSE-SU-2026:2108-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-20262108-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2108-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/SUSE-SU-2026:2108-1
Upstream
CVE (4)
Related
Published
2026-05-29T07:20:10Z
Modified
2026-05-30T23:15:04Z
Summary
Security update for samba
Details

This update for samba fixes the following issues

  • CVE-2026-2340: vfs_worm does not block directory modification (bsc#1261158).
  • CVE-2026-3238: unauthenticated udp packet crashes AD DC nbt server (bsc#1261160).
  • CVE-2026-4408: Remote Code Execution in SAMR (bsc#1261163).
  • CVE-2026-4480: Unauthenticated Remote Code Execution (bsc#1261161).

Non security issues:

  • Fix pthreadpool_tevent race conditions accessing both pthreadpool_tevent.jobs list and pthreadpool_tevent.glue_list (bsc#1252963)
References

Affected packages