CVE-2026-6949
Samba vulnerability analysis and mitigation

Overview

CVE-2026-6949 is a denial-of-service vulnerability in Samba caused by incorrect handling of TSIG packets with DNS name compression. Discovered by Arjun Basnet, Douglas Bagnall, and Andrew Tridgell, the flaw involves incorrect size calculations in TSIG records with compressed DNS names, leading to an out-of-bounds write that can crash the Samba DNS process. A compounding flaw eliminates the authentication requirement, allowing unauthenticated remote attackers to crash the DNS server using crafted TSIG packets. Affected versions span multiple Samba branches across Ubuntu 22.04 LTS, 24.04 LTS, and 26.04 LTS. The CVE is currently in Reserved status with no official CVSS score published; Feedly estimates the severity as Medium (Ubuntu Advisory, Feedly).

Technical details

The root cause is an incorrect size calculation when parsing TSIG DNS records that contain compressed DNS names (CWE-787, Out-of-bounds Write). When Samba processes a crafted TSIG packet, the miscalculation results in a write beyond the allocated buffer, causing the DNS server process to crash. A secondary flaw removes the authentication gate for this code path, meaning no valid credentials are required to trigger the crash — any remote attacker with network access to the DNS port can send a malformed TSIG packet to exploit the vulnerability. No public proof-of-concept code has been identified at this time (Ubuntu Advisory, Feedly).

Impact

Successful exploitation results in a crash of the Samba DNS server process, causing a denial of service for DNS resolution in environments where Samba is used as a domain controller or DNS backend. Because no authentication is required, the attack surface is broad — any network-accessible Samba DNS instance is potentially vulnerable. There is no evidence of confidentiality or integrity impact beyond service disruption; however, prolonged DNS outages in Active Directory environments can cascade into broader authentication and domain service failures (Ubuntu Advisory).

Exploitation steps

  1. Reconnaissance: Identify Samba-based DNS servers (e.g., Active Directory domain controllers running Samba) exposed on UDP/TCP port 53 using network scanning tools such as nmap or Shodan.
  2. Craft malicious TSIG packet: Construct a DNS query containing a TSIG record with a compressed DNS name that triggers the incorrect size calculation in Samba's TSIG parsing code.
  3. Send unauthenticated packet: Transmit the crafted packet to the target's DNS port (UDP 53 or TCP 53) without any authentication credentials, exploiting the secondary flaw that removes the authentication requirement.
  4. Trigger crash: The out-of-bounds write caused by the miscalculated buffer size crashes the Samba DNS server process, resulting in a denial of service for all DNS clients relying on that server (Ubuntu Advisory, Feedly).

Indicators of compromise

  • Network: Unexpected or malformed DNS packets containing TSIG records with compressed names arriving on UDP/TCP port 53 from external or untrusted sources; repeated connection attempts to the DNS port from a single source IP.
  • Logs: Samba DNS service crash logs or core dump files in the Samba log directory (e.g., /var/log/samba/); systemd or init logs showing unexpected restarts of the samba or samba-ad-dc service.
  • Process: Sudden termination of the Samba DNS process (samba or named under Samba); automated service restart events logged by the process supervisor.

Mitigation and workarounds

Ubuntu has released patched Samba package versions addressing CVE-2026-6949: Ubuntu 26.04 LTS (samba 2:4.23.6+dfsg-1ubuntu2.2), Ubuntu 24.04 LTS (samba 2:4.19.5+dfsg-4ubuntu9.7), and Ubuntu 22.04 LTS (samba 2:4.15.13+dfsg-0ubuntu1.13). SUSE has also released updates (SUSE-SU-2026:3363-1), and openSUSE and Slackware advisories have been published. Administrators should apply the standard system update immediately using their distribution's package manager. As a temporary workaround, restricting access to the DNS port (UDP/TCP 53) to trusted networks via firewall rules can reduce exposure until patching is complete (Ubuntu Advisory, SUSE Advisory).

Community reactions

The vulnerability was covered in Linux security aggregators and distribution security lists shortly after disclosure. LinuxCompatible.org noted the broader context of Samba patching critical domain takeover flaws across all branches in the same release cycle. Ubuntu, SUSE, openSUSE, Slackware, and Debian all issued advisories within days of the initial disclosure, reflecting coordinated vendor response. The oss-security mailing list also carried a disclosure thread (LinuxCompatible, oss-sec).

Additional resources


SourceThis report was generated using AI

Related Samba vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-6949NONEN/A
  • Samba logoSamba
  • samba-libs-32bit
NoYesJul 28, 2026
CVE-2026-58224NONEN/A
  • Samba logoSamba
  • samba-winbind-libs
NoYesJul 28, 2026
CVE-2026-58222NONEN/A
  • Samba logoSamba
  • samba-libs-32bit
NoYesJul 28, 2026
CVE-2026-58221NONEN/A
  • Samba logoSamba
  • libldb2
NoYesJul 28, 2026
CVE-2026-58218NONEN/A
  • Samba logoSamba
  • samba-gpupdate
NoYesJul 28, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management