CVE-2026-1933
EUVD-2026-3227527.05.2026, 14:16
A flaw was found in Samba’s handling of NTFS-style reparse points on shares configured with read only = yes. Due to missing SMB-layer access checks, authenticated users with underlying filesystem write permissions may create or delete reparse point metadata through SMB operations even on read-only exports. This could allow modification of SMB-visible file behavior, including converting files into symbolic links or other reparse point types.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| redhat | openshift_container_platform | 4.0 |
| samba | samba | 4.1.0 ≤ 𝑥 < 4.2.2 |
| redhat | enterprise_linux | 7.0 |
| redhat | enterprise_linux | 8.0 |
| redhat | enterprise_linux | 9.0 |
| redhat | enterprise_linux | 10.0 |
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | 0:4.23.5-109.el10_2 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 10.0 Extended Update Support | 0:4.21.3-114.el10_0.1 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 8 | 0:4.19.4-16.el8_10 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | 0:4.15.5-16.el8_6.1 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On | 0:4.15.5-16.el8_6.1 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 8.8 Telecommunications Update Service | 0:4.17.5-7.el8_8.1 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | 0:4.17.5-7.el8_8.1 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 9 | 0:4.23.5-10.el9_8 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | 0:4.17.5-105.el9_2.5 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions | 0:4.19.4-105.el9_4.4 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 9.6 Extended Update Support | 0:4.21.3-14.el9_6.1 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat OpenShift Container Platform 4.19 | 4.19.9.6.202606241344-0 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat OpenShift Container Platform 4.20 | 4.20.9.6.202608121719-0 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat OpenShift Container Platform 4.21 | 4.21.9.6.202608122143-0 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat OpenShift Container Platform 4.22 | 4.22.9.8.202608130832-0 ≤ 𝑥 < * | ADP |
Debian Releases
Debian Product | |||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| samba |
|
Ubuntu Releases
Red Hat Enterprise Linux Releases
Red Hat Product | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|
| ctdb |
| ||||||||||
| ldb-tools |
| ||||||||||
| libldb |
| ||||||||||
| libldb-devel |
| ||||||||||
| libnetapi |
| ||||||||||
| libnetapi-devel |
| ||||||||||
| libsmbclient |
| ||||||||||
| libsmbclient-devel |
| ||||||||||
| libwbclient |
| ||||||||||
| libwbclient-devel |
| ||||||||||
| python3-ldb |
| ||||||||||
| python3-samba |
| ||||||||||
| python3-samba-dc |
| ||||||||||
| python3-samba-devel |
| ||||||||||
| python3-samba-test |
| ||||||||||
| samba |
| ||||||||||
| samba-client |
| ||||||||||
| samba-client-libs |
| ||||||||||
| samba-common |
| ||||||||||
| samba-common-libs |
| ||||||||||
| samba-common-tools |
| ||||||||||
| samba-dc-libs |
| ||||||||||
| samba-dcerpc |
| ||||||||||
| samba-devel |
| ||||||||||
| samba-gpupdate |
| ||||||||||
| samba-krb5-printing |
| ||||||||||
| samba-ldb-ldap-modules |
| ||||||||||
| samba-libs |
| ||||||||||
| samba-pidl |
| ||||||||||
| samba-test |
| ||||||||||
| samba-test-libs |
| ||||||||||
| samba-tools |
| ||||||||||
| samba-usershares |
| ||||||||||
| samba-vfs-iouring |
| ||||||||||
| samba-winbind |
| ||||||||||
| samba-winbind-clients |
| ||||||||||
| samba-winbind-krb5-locator |
| ||||||||||
| samba-winbind-modules |
| ||||||||||
| samba-winexe |
|
Common Weakness Enumeration
References