
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-58218 is a denial-of-service vulnerability in the Samba DNS server affecting its TKEY name registration handling. Unauthenticated remote attackers can overwhelm the server with TKEY registration requests, exhausting the cache used to filter TSIG requests, which prevents authenticated users from performing DNS TSIG signing. The vulnerability was disclosed in July 2026 and affects Samba packages across Ubuntu 22.04 LTS, 24.04 LTS, and 26.04 LTS. The CVE is currently in "Reserved" status with no official CVSS score published; Feedly estimates the severity as Medium (Ubuntu Advisory, Feedly).
The root cause is improper handling of TKEY name registration requests in Samba's DNS server component, which allows a finite cache used to filter TSIG requests to be exhausted without authentication (CWE-400: Uncontrolled Resource Consumption). An unauthenticated attacker can flood the server with TKEY registration requests, filling the TKEY name cache and rendering TSIG-based authentication inoperable for legitimate clients. The vulnerability was discovered by Andrew Tridgell and Tristan Madani (Ubuntu Advisory). No public proof-of-concept exploit code has been identified at this time.
Successful exploitation results in a denial-of-service condition affecting DNS TSIG signing operations, meaning authenticated users and services relying on TSIG-signed DNS updates or queries will be unable to complete those operations. The impact is limited to availability — there is no reported confidentiality or integrity compromise from this specific vulnerability. Environments using Samba as an Active Directory Domain Controller with DNS TSIG authentication are most at risk, as disruption of TSIG signing can impair secure DNS update workflows (Ubuntu Advisory).
nmap or dig.Ubuntu has released patched Samba package versions addressing CVE-2026-58218 and related vulnerabilities: Ubuntu 26.04 LTS (samba 2:4.23.6+dfsg-1ubuntu2.2), Ubuntu 24.04 LTS (samba 2:4.19.5+dfsg-4ubuntu9.7), and Ubuntu 22.04 LTS (samba 2:4.15.13+dfsg-0ubuntu1.13). A standard system update (apt update && apt upgrade) will apply the necessary fixes. SUSE and openSUSE have also released security updates (SUSE-SU-2026:3363-1) (Ubuntu Advisory, SUSE Advisory). As a network-level workaround, restrict access to the Samba DNS service (port 53) to trusted IP ranges to reduce exposure until patching is complete.
The vulnerability was part of a broader Samba security advisory batch released in late July 2026, which also included a critical domain takeover flaw (CVE-2026-58221), drawing significant attention from the Linux security community. Coverage appeared across Linux-focused news aggregators and distribution security lists, including openSUSE, SUSE, Ubuntu, Slackware, and Debian advisories, indicating broad downstream impact (Linux Compatible, openSUSE). The oss-security mailing list also carried disclosure details (oss-sec).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."