CVE-2026-58218
Samba vulnerability analysis and mitigation

Overview

CVE-2026-58218 is a denial-of-service vulnerability in the Samba DNS server affecting its TKEY name registration handling. Unauthenticated remote attackers can overwhelm the server with TKEY registration requests, exhausting the cache used to filter TSIG requests, which prevents authenticated users from performing DNS TSIG signing. The vulnerability was disclosed in July 2026 and affects Samba packages across Ubuntu 22.04 LTS, 24.04 LTS, and 26.04 LTS. The CVE is currently in "Reserved" status with no official CVSS score published; Feedly estimates the severity as Medium (Ubuntu Advisory, Feedly).

Technical details

The root cause is improper handling of TKEY name registration requests in Samba's DNS server component, which allows a finite cache used to filter TSIG requests to be exhausted without authentication (CWE-400: Uncontrolled Resource Consumption). An unauthenticated attacker can flood the server with TKEY registration requests, filling the TKEY name cache and rendering TSIG-based authentication inoperable for legitimate clients. The vulnerability was discovered by Andrew Tridgell and Tristan Madani (Ubuntu Advisory). No public proof-of-concept exploit code has been identified at this time.

Impact

Successful exploitation results in a denial-of-service condition affecting DNS TSIG signing operations, meaning authenticated users and services relying on TSIG-signed DNS updates or queries will be unable to complete those operations. The impact is limited to availability — there is no reported confidentiality or integrity compromise from this specific vulnerability. Environments using Samba as an Active Directory Domain Controller with DNS TSIG authentication are most at risk, as disruption of TSIG signing can impair secure DNS update workflows (Ubuntu Advisory).

Exploitation steps

  1. Reconnaissance: Identify Samba DNS servers (acting as AD Domain Controllers) exposed on the network by scanning for port 53 (DNS) and confirming Samba service banners or version information using tools like nmap or dig.
  2. Craft TKEY registration requests: Prepare a high volume of DNS TKEY registration request packets targeting the Samba DNS server. TKEY records are used in DNS for key exchange and can be sent without prior authentication.
  3. Flood the TKEY name cache: Continuously send TKEY registration requests with varied names to exhaust the server's finite TKEY name cache, which is used to filter and validate TSIG requests.
  4. Observe denial of service: Once the cache is exhausted, legitimate authenticated clients attempting DNS TSIG signing operations will fail, as the server can no longer process their TSIG-authenticated requests, effectively disrupting DNS update workflows (Ubuntu Advisory).

Indicators of compromise

  • Network: Unusually high volume of DNS TKEY query/registration packets from one or more source IPs targeting the Samba DNS server on port 53 (UDP/TCP).
  • Logs: Samba DNS or system logs showing repeated TKEY registration attempts, cache exhaustion warnings, or TSIG authentication failures from legitimate clients.
  • Service Behavior: Authenticated clients reporting failures in DNS TSIG signing operations or dynamic DNS updates that previously succeeded; Samba DNS service showing degraded responsiveness to TSIG-authenticated requests.

Mitigation and workarounds

Ubuntu has released patched Samba package versions addressing CVE-2026-58218 and related vulnerabilities: Ubuntu 26.04 LTS (samba 2:4.23.6+dfsg-1ubuntu2.2), Ubuntu 24.04 LTS (samba 2:4.19.5+dfsg-4ubuntu9.7), and Ubuntu 22.04 LTS (samba 2:4.15.13+dfsg-0ubuntu1.13). A standard system update (apt update && apt upgrade) will apply the necessary fixes. SUSE and openSUSE have also released security updates (SUSE-SU-2026:3363-1) (Ubuntu Advisory, SUSE Advisory). As a network-level workaround, restrict access to the Samba DNS service (port 53) to trusted IP ranges to reduce exposure until patching is complete.

Community reactions

The vulnerability was part of a broader Samba security advisory batch released in late July 2026, which also included a critical domain takeover flaw (CVE-2026-58221), drawing significant attention from the Linux security community. Coverage appeared across Linux-focused news aggregators and distribution security lists, including openSUSE, SUSE, Ubuntu, Slackware, and Debian advisories, indicating broad downstream impact (Linux Compatible, openSUSE). The oss-security mailing list also carried disclosure details (oss-sec).

Additional resources


SourceThis report was generated using AI

Related Samba vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-6949NONEN/A
  • Samba logoSamba
  • samba-libs-32bit
NoYesJul 28, 2026
CVE-2026-58224NONEN/A
  • Samba logoSamba
  • samba-winbind-libs
NoYesJul 28, 2026
CVE-2026-58222NONEN/A
  • Samba logoSamba
  • samba-libs-32bit
NoYesJul 28, 2026
CVE-2026-58221NONEN/A
  • Samba logoSamba
  • libldb2
NoYesJul 28, 2026
CVE-2026-58218NONEN/A
  • Samba logoSamba
  • samba-gpupdate
NoYesJul 28, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management