{"id":"SUSE-SU-2026:2072-1","summary":"Security update for samba","details":"This update for samba fixes the following issues\n\n- CVE-2026-2340: vfs_worm does not block directory modification (bsc#1261158).\n- CVE-2026-3012: group policy certificate enrollment uses http: // without validation (bsc#1261159).\n- CVE-2026-3238: unauthenticated udp packet crashes AD DC nbt server (bsc#1261160).\n- CVE-2026-4408: Remote Code Execution in SAMR (bsc#1261163).\n- CVE-2026-4480: Unauthenticated Remote Code Execution (bsc#1261161).\n","modified":"2026-05-27T08:16:17.752472984Z","published":"2026-05-26T12:35:17Z","related":["CVE-2026-2340","CVE-2026-3012","CVE-2026-3238","CVE-2026-4408","CVE-2026-4480"],"upstream":["CVE-2026-2340","CVE-2026-3012","CVE-2026-3238","CVE-2026-4408","CVE-2026-4480"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20262072-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261158"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261159"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261160"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261161"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261163"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-2340"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-3012"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-3238"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-4408"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-4480"}],"schema_version":"1.7.5"}