
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-6949 is a denial-of-service vulnerability in Samba caused by incorrect handling of TSIG packets with DNS name compression. Discovered by Arjun Basnet, Douglas Bagnall, and Andrew Tridgell, the flaw involves incorrect size calculations in TSIG records with compressed DNS names, leading to an out-of-bounds write that can crash the Samba DNS process. A compounding flaw eliminates the authentication requirement, allowing unauthenticated remote attackers to crash the DNS server using crafted TSIG packets. Affected versions span multiple Samba branches across Ubuntu 22.04 LTS, 24.04 LTS, and 26.04 LTS. The CVE is currently in Reserved status with no official CVSS score published; Feedly estimates the severity as Medium (Ubuntu Advisory, Feedly).
The root cause is an incorrect size calculation when parsing TSIG DNS records that contain compressed DNS names (CWE-787, Out-of-bounds Write). When Samba processes a crafted TSIG packet, the miscalculation results in a write beyond the allocated buffer, causing the DNS server process to crash. A secondary flaw removes the authentication gate for this code path, meaning no valid credentials are required to trigger the crash — any remote attacker with network access to the DNS port can send a malformed TSIG packet to exploit the vulnerability. No public proof-of-concept code has been identified at this time (Ubuntu Advisory, Feedly).
Successful exploitation results in a crash of the Samba DNS server process, causing a denial of service for DNS resolution in environments where Samba is used as a domain controller or DNS backend. Because no authentication is required, the attack surface is broad — any network-accessible Samba DNS instance is potentially vulnerable. There is no evidence of confidentiality or integrity impact beyond service disruption; however, prolonged DNS outages in Active Directory environments can cascade into broader authentication and domain service failures (Ubuntu Advisory).
/var/log/samba/); systemd or init logs showing unexpected restarts of the samba or samba-ad-dc service.samba or named under Samba); automated service restart events logged by the process supervisor.Ubuntu has released patched Samba package versions addressing CVE-2026-6949: Ubuntu 26.04 LTS (samba 2:4.23.6+dfsg-1ubuntu2.2), Ubuntu 24.04 LTS (samba 2:4.19.5+dfsg-4ubuntu9.7), and Ubuntu 22.04 LTS (samba 2:4.15.13+dfsg-0ubuntu1.13). SUSE has also released updates (SUSE-SU-2026:3363-1), and openSUSE and Slackware advisories have been published. Administrators should apply the standard system update immediately using their distribution's package manager. As a temporary workaround, restricting access to the DNS port (UDP/TCP 53) to trusted networks via firewall rules can reduce exposure until patching is complete (Ubuntu Advisory, SUSE Advisory).
The vulnerability was covered in Linux security aggregators and distribution security lists shortly after disclosure. LinuxCompatible.org noted the broader context of Samba patching critical domain takeover flaws across all branches in the same release cycle. Ubuntu, SUSE, openSUSE, Slackware, and Debian all issued advisories within days of the initial disclosure, reflecting coordinated vendor response. The oss-security mailing list also carried a disclosure thread (LinuxCompatible, oss-sec).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."