CVE-2026-3238 Details
Description
A flaw was found in Samba’s WINS server component when running as an Active Directory Domain Controller. The WINS protocol handlers for certain request types did not properly validate incoming packets, allowing an unauthenticated remote attacker to trigger a NULL pointer dereference and crash the WINS service using specially crafted UDP packets.
A denial-of-service vulnerability has been identified in the WINS server component of Samba when it is configured as an Active Directory Domain Controller. The issue arises because the WINS protocol handlers for certain request types fail to properly validate incoming packets. This flaw allows an unauthenticated remote attacker to send specially crafted UDP packets that trigger a NULL pointer dereference, causing the WINS service to crash. Although the service may automatically restart, the vulnerability can be easily exploited repeatedly, leading to continuous unavailability of the WINS service.
To address this vulnerability, Samba administrators should upgrade to Samba versions 4.22.10, 4.23.8, or 4.24.3, all of which include the necessary patch. For deployments that do not require Samba's WINS functionality, WINS support can be disabled by removing the 'wins support = yes' setting from the Samba configuration.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 8, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-476 | NULL Pointer Dereference | redhat-SADP |
| CWE-476 | NULL Pointer Dereference | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
8 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 1, 2026 | CVE Modified | [email protected] |
| Sep 1, 2026 | CVE Modified | redhat-SADP |
| Jul 23, 2026 | CVE Translated | [email protected] |
| Jul 15, 2026 | CVE Modified | redhat-SADP |
| Jun 30, 2026 | CVE Modified | redhat-SADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 8, 2026 | New CVE Received | [email protected] |