CVE-2026-58224 Details
Description
A flaw was found in Samba's CTDB, the clustered database service used by Samba. Insufficient integrity validation of received CTDB protocol packets allows malformed packets containing invalid field lengths, improperly terminated strings, or inconsistent packet sizes to be processed without adequate bounds checking. A remote attacker with access to the CTDB private network may trigger a denial of service through process crashes or excessive memory consumption and, in limited cases, disclose adjacent memory contents.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 18, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-58224 | [email protected] | Third Party Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2502720 | [email protected] | Issue TrackingThird Party Advisory |
| https://bugzilla.samba.org/show_bug.cgi?id=16085 | [email protected] | Issue TrackingMitigationVendor Advisory |
| https://www.samba.org/samba/security/CVE-2026-58224-advisory.html | [email protected] | Mailing ListVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-353 | Missing Support for Integrity Check | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| samba samba | <= 4.2.0 |
CPE
Remediation
| |
| redhat enterprise linux | 6.0 7.0 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 23, 2026 | Modified Analysis | [email protected] |
| Aug 31, 2026 | CVE Modified | [email protected] |
| Aug 26, 2026 | CVE Modified | [email protected] |
| Aug 26, 2026 | Initial Analysis | [email protected] |
| Aug 18, 2026 | CVE Modified | CISA-ADP |
| Aug 14, 2026 | New CVE Received | [email protected] |