CVE-2026-58216
Samba vulnerability analysis and mitigation

Overview

CVE-2026-58216 is a denial-of-service vulnerability in Samba's KDC (Key Distribution Center) process caused by improper handling of malformed ASN.1 data in Kerberos kpasswd packets. Discovered by Tristan Madani, the flaw allows authenticated users to crash the Samba server by triggering a read of unallocated memory. It affects Samba packages across Ubuntu 22.04 LTS, 24.04 LTS, and 26.04 LTS, and is estimated to be of Medium severity (Ubuntu Advisory, Feedly). The CVE is currently in Reserved status with no official CVSS score published yet.

Technical details

The root cause is improper input validation when parsing ASN.1-encoded data within Kerberos kpasswd packets, classified under CWE-125 (Out-of-bounds Read). An authenticated attacker can send a specially crafted kpasswd packet to the Samba KDC process, causing it to read from unallocated memory and subsequently crash. Exploitation requires prior authentication, limiting the attack surface, but no special privileges beyond a valid domain credential are needed (Ubuntu Advisory, Feedly). No public proof-of-concept exploit code has been identified at this time.

Impact

Successful exploitation results in a crash of the Samba KDC process, causing a denial of service for Kerberos-dependent authentication services. This can disrupt domain authentication for all users and services relying on the affected Samba domain controller. There is no known data disclosure or integrity impact — confidentiality and integrity are not affected, only availability (Ubuntu Advisory, Feedly).

Exploitation steps

  1. Authentication: Obtain valid Kerberos credentials for the target Samba domain (e.g., a standard domain user account).
  2. Craft malformed kpasswd packet: Construct a Kerberos kpasswd request containing malformed or invalid ASN.1 encoding — for example, incorrect length fields, truncated structures, or invalid tag values within the ASN.1 DER-encoded payload.
  3. Send packet to KDC: Transmit the crafted kpasswd packet to the target Samba KDC service (typically UDP/TCP port 464) using a Kerberos client library or raw socket tool.
  4. Trigger crash: The KDC process attempts to parse the malformed ASN.1 data, reads from unallocated memory, and crashes — resulting in a denial of service for all Kerberos authentication on the domain (Ubuntu Advisory, Feedly).

Indicators of compromise

  • Network: Unexpected or repeated connections to port 464 (kpasswd) from authenticated users who are not performing legitimate password changes; anomalous kpasswd traffic volume from a single source.
  • Logs: Samba KDC crash logs or core dumps in /var/log/samba/ or system journal; entries indicating segmentation faults or memory access errors in the samba or samba-ad-dc service.
  • Process: Unexpected termination or restart of the samba daemon or samba-ad-dc service; automated service manager (systemd) logs showing repeated restarts of the KDC process.

Mitigation and workarounds

Ubuntu has released patched Samba package versions addressing CVE-2026-58216: Ubuntu 26.04 LTS should update to samba 2:4.23.6+dfsg-1ubuntu2.2, Ubuntu 24.04 LTS to samba 2:4.19.5+dfsg-4ubuntu9.7, and Ubuntu 22.04 LTS to samba 2:4.15.13+dfsg-0ubuntu1.13. A standard system update (apt update && apt upgrade) will apply the fix. SUSE and openSUSE have also released security updates (SUSE-SU-2026:3363-1) (Ubuntu Advisory, SUSE Advisory). As a temporary workaround, restricting access to port 464 (kpasswd) to trusted hosts only can reduce exposure until patching is possible.

Community reactions

The vulnerability was disclosed alongside several other Samba flaws in late July 2026, with broader community coverage focusing on the more severe domain takeover vulnerability (CVE-2026-58221) in the same advisory batch. Linux distribution vendors including Ubuntu, SUSE, openSUSE, Slackware, and Debian moved quickly to release patches (Ubuntu Advisory, SUSE Advisory). Community aggregators noted the patch release under the headline "Samba patches critical domain takeover flaws across all branches," reflecting that CVE-2026-58216 was considered a lower-severity item within the broader release (LinuxCompatible).

Additional resources


SourceThis report was generated using AI

Related Samba vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-58222HIGH8.8
  • Samba logoSamba
  • samba
NoYesJul 30, 2026
CVE-2026-58216MEDIUM5.3
  • Samba logoSamba
  • samba-krb5-printing
NoYesJul 30, 2026
CVE-2026-58218MEDIUM5.3
  • Samba logoSamba
  • ldb-tools
NoYesJul 30, 2026
CVE-2026-6949NONEN/A
  • Samba logoSamba
  • libnetapi
NoYesJul 28, 2026
CVE-2026-58224NONEN/A
  • Samba logoSamba
  • samba-winbind
NoYesJul 28, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management