CVE-2026-58218 Details
Description
A flaw was found in Samba's internal DNS server where unauthenticated TKEY registration requests were added to the TKEY name cache before being rejected. A remote, unauthenticated attacker can exploit this behavior by sending a large number of TKEY requests with arbitrary names, exhausting the cache and evicting legitimate TKEY entries. This can prevent legitimate TSIG authentication for signed DNS queries, resulting in a denial of service.
A denial-of-service vulnerability has been identified in Samba's internal DNS server, affecting all versions since 4.0. The issue arises from the handling of unauthenticated TKEY registration requests, which are prematurely added to the TKEY name cache before being properly validated. This flaw allows remote, unauthenticated attackers to send numerous TKEY requests with arbitrary names, filling up the cache and removing legitimate TKEY entries. As a result, this disruption can block valid TSIG authentication for signed DNS queries, causing a denial-of-service condition.
Users can upgrade to Samba versions 4.22.11, 4.23.10, or 4.24.5, all of which include the necessary patch. Alternatively, the vulnerability can be mitigated by using the external BIND9 DLZ backend for DNS management, as this issue does not affect BIND9 deployments.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-410 | Insufficient Resource Pool | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 30, 2026 | CVE Modified | CISA-ADP |
| Jul 30, 2026 | New CVE Received | [email protected] |