CVE-2026-58224

A flaw was found in Samba's CTDB, the clustered database service used by Samba. Insufficient integrity validation of received CTDB protocol packets allows malformed packets containing invalid field lengths, improperly terminated strings, or inconsistent packet sizes to be processed without adequate bounds checking. A remote attacker with access to the CTDB private network may trigger a denial of service through process crashes or excessive memory consumption and, in limited cases, disclose adjacent memory contents.
References
Link Resource
https://access.redhat.com/security/cve/CVE-2026-58224 Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2502720 Issue Tracking Third Party Advisory
https://bugzilla.samba.org/show_bug.cgi?id=16085 Issue Tracking Mitigation Vendor Advisory
https://www.samba.org/samba/security/CVE-2026-58224-advisory.html Mailing List Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-08-14 15:17

Updated : 2026-08-31 12:17


NVD link : CVE-2026-58224

Mitre link : CVE-2026-58224

CVE.ORG link : CVE-2026-58224


JSON object : View

Products Affected

redhat

  • enterprise_linux

samba

  • samba
CWE
CWE-353

Missing Support for Integrity Check