CVE-2026-3238

EUVD-2026-35033
A flaw was found in Samba’s WINS server component when running as an Active Directory Domain Controller. The WINS protocol handlers for certain request types did not properly validate incoming packets, allowing an unauthenticated remote attacker to trigger a NULL pointer dereference and crash the WINS service using specially crafted UDP packets.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 22%
Debian logo
Debian Releases
Debian Product
Codename
samba
bookworm
vulnerable
bookworm (security)
2:4.17.12+dfsg-0+deb12u4
fixed
bullseye
vulnerable
bullseye (security)
vulnerable
forky
2:4.24.3+dfsg-1
fixed
sid
2:4.24.3+dfsg-1
fixed
trixie
vulnerable
trixie (security)
2:4.22.8+dfsg-0+deb13u2
fixed