{"id":"SUSE-SU-2026:2076-1","summary":"Security update for samba","details":"This update for samba fixes the following issues\n\nSecurity issues:\n\n- CVE-2026-1933: Missing access check on reparse point operations (bsc#1261188).\n- CVE-2026-2340: vfs_worm does not block directory modification (bsc#1261158).\n- CVE-2026-3012: group policy certificate enrollment uses http: // without validation (bsc#1261159).\n- CVE-2026-3238: unauthenticated udp packet crashes AD DC nbt server (bsc#1261160).\n- CVE-2026-4408: Remote Code Execution in SAMR (bsc#1261163).\n- CVE-2026-4480: Unauthenticated Remote Code Execution (bsc#1261161).\n\nNon security issue:\n\n- network:samba:STABLE/samba: 'use-kerberos=desired' broken / Dolphin requires login for Samba shares (bsc#1255755).\n- Generated dynamic profile based on path to special 'printers' share. (bsc#1259441).\n- Fix regression 'use-kerberos=desired' broken doesn't even try to authenticate with kerberos and instead fallsback \nto NTLM (bsc#1255755).\n- Fix memory leak using cups parsed options and filename allocated when processing end of printing job (bsc#1257200).\n- Fix manpage for 'net offlinejoin requestodj'.\n- Fix 'ctdbd socket' documentation in manpage for smb.conf\n- Fix rpc workers with long living clients from growing server\n memory keytab and increasing memory used by workers (bsc#1257200).\n\n","modified":"2026-05-27T08:16:17.752385686Z","published":"2026-05-26T12:36:51Z","related":["CVE-2026-1933","CVE-2026-2340","CVE-2026-3012","CVE-2026-3238","CVE-2026-4408","CVE-2026-4480"],"upstream":["CVE-2026-1933","CVE-2026-2340","CVE-2026-3012","CVE-2026-3238","CVE-2026-4408","CVE-2026-4480"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20262076-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1255755"},{"type":"REPORT","url":"https://bugzilla.suse.com/1257200"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259441"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261158"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261159"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261160"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261161"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261163"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261188"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-1933"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-2340"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-3012"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-3238"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-4408"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-4480"}],"schema_version":"1.7.5"}