{"id":"SUSE-SU-2026:2108-1","summary":"Security update for samba","details":"This update for samba fixes the following issues\n\n- CVE-2026-2340: vfs_worm does not block directory modification (bsc#1261158).\n- CVE-2026-3238: unauthenticated udp packet crashes AD DC nbt server (bsc#1261160).\n- CVE-2026-4408: Remote Code Execution in SAMR (bsc#1261163).\n- CVE-2026-4480: Unauthenticated Remote Code Execution (bsc#1261161).\n\nNon security issues:\n  \n- Fix pthreadpool_tevent race conditions accessing both\n pthreadpool_tevent.jobs list and pthreadpool_tevent.glue_list\n (bsc#1252963)\n","modified":"2026-05-30T23:15:04.772669785Z","published":"2026-05-29T07:20:10Z","related":["CVE-2026-2340","CVE-2026-3238","CVE-2026-4408","CVE-2026-4480"],"upstream":["CVE-2026-2340","CVE-2026-3238","CVE-2026-4408","CVE-2026-4480"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20262108-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1252963"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261158"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261160"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261161"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261163"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-2340"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-3238"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-4408"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-4480"}],"schema_version":"1.7.5"}