CVE-2026-58224

EUVD-2026-58669
A flaw was found in Samba's CTDB, the clustered database service used by Samba. Insufficient integrity validation of received CTDB protocol packets allows malformed packets containing invalid field lengths, improperly terminated strings, or inconsistent packet sizes to be processed without adequate bounds checking. A remote attacker with access to the CTDB private network may trigger a denial of service through process crashes or excessive memory consumption and, in limited cases, disclose adjacent memory contents.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 MEDIUM
ADJACENT_NETWORK
LOW
NONE
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Debian logo
Debian Releases
Debian Product
Codename
samba
bookworm
vulnerable
bookworm (security)
vulnerable
bullseye
vulnerable
bullseye (security)
vulnerable
forky
2:4.24.5+dfsg-1
fixed
sid
2:4.24.5+dfsg-1
fixed
trixie
vulnerable
trixie (security)
2:4.22.10+dfsg-0+deb13u2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
samba
bionic
needs-triage
focal
needs-triage
jammy
Fixed 2:4.15.13+dfsg-0ubuntu1.13
released
noble
Fixed 2:4.19.5+dfsg-4ubuntu9.7
released
resolute
Fixed 2:4.23.6+dfsg-1ubuntu2.2
released
trusty
needs-triage
xenial
needs-triage