Samba: vfs_worm does not block directory modification
Published May 27, 2026
6.5
MEDIUMCVSS 3.1
EPSS 0.94%
Description
A flaw was found in Samba’s vfs_worm module. The module is intended to provide write-once, read-many (WORM) protections by preventing modification of files after a configurable grace period. Due to insufficient validation during rename operations, an authenticated user with write access to a share could overwrite a protected file by renaming a newly created file over the existing WORM-protected file.
Affected products
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||
|---|---|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 7 | affected |
| |||
| Red Hat | Red Hat OpenShift Container Platform 4 | affected |
|
- 4.0
- ≥ 4.1.0
- 7.0
- 8.0
- 9.0
- 10.0
No data.
Red Hat Enterprise Linux 10
samba-0:4.23.5-109.el10_2
Fixed · RHSA-2026:22963
Red Hat Enterprise Linux 10.0 Extended Update Support
samba-0:4.21.3-114.el10_0.1
Fixed · RHSA-2026:28055
Red Hat Enterprise Linux 8
samba-0:4.19.4-16.el8_10
Fixed · RHSA-2026:22644
Red Hat Enterprise Linux 8
samba-0:4.19.4-16.el8_10
Fixed · RHSA-2026:22644
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
samba-0:4.15.5-16.el8_6.1
Fixed · RHSA-2026:28057
Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On
samba-0:4.15.5-16.el8_6.1
Fixed · RHSA-2026:28057
Red Hat Enterprise Linux 8.8 Telecommunications Update Service
samba-0:4.17.5-7.el8_8.1
Fixed · RHSA-2026:28056
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
samba-0:4.17.5-7.el8_8.1
Fixed · RHSA-2026:28056
Red Hat Enterprise Linux 9
samba-0:4.23.5-10.el9_8
Fixed · RHSA-2026:25049
Red Hat Enterprise Linux 9
samba-0:4.23.5-10.el9_8
Fixed · RHSA-2026:25049
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions
samba-0:4.17.5-105.el9_2.5
Fixed · RHSA-2026:28054
Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions
samba-0:4.19.4-105.el9_4.4
Fixed · RHSA-2026:28053
Red Hat Enterprise Linux 9.6 Extended Update Support
samba-0:4.21.3-14.el9_6.1
Fixed · RHSA-2026:25979
Red Hat OpenShift Container Platform 4.12
rhcos-412.86.202608241157-0
Fixed · RHSA-2026:59831
Red Hat OpenShift Container Platform 4.12
rhcos-412.86.202609082051-0
Fixed · RHSA-2026:65907
Red Hat OpenShift Container Platform 4.13
rhcos-413.92.202609080414-0
Fixed · RHSA-2026:65839
Red Hat OpenShift Container Platform 4.14
rhcos-414.92.202608172040-0
Fixed · RHSA-2026:56786
Red Hat OpenShift Container Platform 4.14
rhcos-414.92.202609011250-0
Fixed · RHSA-2026:62409
Red Hat OpenShift Container Platform 4.15
rhcos-415.92.202608180329-0
Fixed · RHSA-2026:56911
Red Hat OpenShift Container Platform 4.16
rhcos-416.94.202608150307-0
Fixed · RHSA-2026:56853
Red Hat OpenShift Container Platform 4.16
rhcos-416.94.202609011112-0
Fixed · RHSA-2026:62549
Red Hat OpenShift Container Platform 4.17
rhcos-417.94.202608250221-0
Fixed · RHSA-2026:60019
Red Hat OpenShift Container Platform 4.18
rhcos-418.94.202608142238-0
Fixed · RHSA-2026:57483
Red Hat OpenShift Container Platform 4.18
rhcos-418.94.202609031320-0
Fixed · RHSA-2026:65851
Red Hat OpenShift Container Platform 4.19
rhcos-4.19.9.6.202606241344-0
Fixed · RHSA-2026:29863
Red Hat Enterprise Linux 6
samba
Out of support scope
Red Hat Enterprise Linux 6
samba4
Out of support scope
Red Hat Enterprise Linux 7
samba
Will not fix
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-8
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | samba-0:4.23.5-109.el10_2 | Fixed | RHSA-2026:22963 |
| Red Hat Enterprise Linux 10.0 Extended Update Support | samba-0:4.21.3-114.el10_0.1 | Fixed | RHSA-2026:28055 |
| Red Hat Enterprise Linux 8 | samba-0:4.19.4-16.el8_10 | Fixed | RHSA-2026:22644 |
| Red Hat Enterprise Linux 8 | samba-0:4.19.4-16.el8_10 | Fixed | RHSA-2026:22644 |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | samba-0:4.15.5-16.el8_6.1 | Fixed | RHSA-2026:28057 |
| Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On | samba-0:4.15.5-16.el8_6.1 | Fixed | RHSA-2026:28057 |
| Red Hat Enterprise Linux 8.8 Telecommunications Update Service | samba-0:4.17.5-7.el8_8.1 | Fixed | RHSA-2026:28056 |
| Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | samba-0:4.17.5-7.el8_8.1 | Fixed | RHSA-2026:28056 |
| Red Hat Enterprise Linux 9 | samba-0:4.23.5-10.el9_8 | Fixed | RHSA-2026:25049 |
| Red Hat Enterprise Linux 9 | samba-0:4.23.5-10.el9_8 | Fixed | RHSA-2026:25049 |
| Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | samba-0:4.17.5-105.el9_2.5 | Fixed | RHSA-2026:28054 |
| Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions | samba-0:4.19.4-105.el9_4.4 | Fixed | RHSA-2026:28053 |
| Red Hat Enterprise Linux 9.6 Extended Update Support | samba-0:4.21.3-14.el9_6.1 | Fixed | RHSA-2026:25979 |
| Red Hat OpenShift Container Platform 4.12 | rhcos-412.86.202608241157-0 | Fixed | RHSA-2026:59831 |
| Red Hat OpenShift Container Platform 4.12 | rhcos-412.86.202609082051-0 | Fixed | RHSA-2026:65907 |
| Red Hat OpenShift Container Platform 4.13 | rhcos-413.92.202609080414-0 | Fixed | RHSA-2026:65839 |
| Red Hat OpenShift Container Platform 4.14 | rhcos-414.92.202608172040-0 | Fixed | RHSA-2026:56786 |
| Red Hat OpenShift Container Platform 4.14 | rhcos-414.92.202609011250-0 | Fixed | RHSA-2026:62409 |
| Red Hat OpenShift Container Platform 4.15 | rhcos-415.92.202608180329-0 | Fixed | RHSA-2026:56911 |
| Red Hat OpenShift Container Platform 4.16 | rhcos-416.94.202608150307-0 | Fixed | RHSA-2026:56853 |
| Red Hat OpenShift Container Platform 4.16 | rhcos-416.94.202609011112-0 | Fixed | RHSA-2026:62549 |
| Red Hat OpenShift Container Platform 4.17 | rhcos-417.94.202608250221-0 | Fixed | RHSA-2026:60019 |
| Red Hat OpenShift Container Platform 4.18 | rhcos-418.94.202608142238-0 | Fixed | RHSA-2026:57483 |
| Red Hat OpenShift Container Platform 4.18 | rhcos-418.94.202609031320-0 | Fixed | RHSA-2026:65851 |
| Red Hat OpenShift Container Platform 4.19 | rhcos-4.19.9.6.202606241344-0 | Fixed | RHSA-2026:29863 |
| Red Hat Enterprise Linux 6 | samba | Out of support scope | n/a |
| Red Hat Enterprise Linux 6 | samba4 | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | samba | Will not fix | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-8 | Affected | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
Administrators can mitigate this issue by:
Setting read-only permissions on protected files at the underlying filesystem level will prevent modifications.
Configuring ```worm:grace_period = 0``` (zero or less) in smb.conf will eliminate the writable grace period (will eliminate the window in which the rename can happen), understanding that this may impact workflows requiring multi-step file creation.
Red Hat statement
This vulnerability is rated Moderate severity because exploitation requires authenticated write access to a Samba share already configured to permit file creation and modification. The flaw affects the vfs_worm module, which provides additional immutability protections for files after a configurable grace period. Due to improper handling of rename operations, a user with existing write permissions could overwrite files that should have become immutable under the WORM policy. The vulnerability does not bypass underlying filesystem access controls or grant additional privileges beyond those already assigned to the authenticated user. However, because the primary purpose of the vfs_worm module is to protect file integrity, the ability to modify protected files results in a high integrity impact.
Red Hat mitigation
Administrators can mitigate this issue by: Setting read-only permissions on protected files at the underlying filesystem level will prevent modifications. Configuring ```worm:grace_period = 0``` (zero or less) in smb.conf will eliminate the writable grace period (will eliminate the window in which the rename can happen), understanding that this may impact workflows requiring multi-step file creation.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed May 29, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
May–Oct 2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (3 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.94% (0.00939) | 59.50th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.47% (0.00470) | 36.77th | v5 (v2026.06.15) |
| May 28, 2026 | 0.03% (0.00025) | 7.55th | v4 (v2025.03.14) |
References (28)
- https://access.redhat.com/errata/RHSA-2026:22644 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:22963 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:25049 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:25979 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:28053 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:28054 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:28055 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:28056 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:28057 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:29863 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:56786 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:56853 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:56911 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:57483 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:59831 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:60019 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:62409 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:62549 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:65839 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:65851 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:65907 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:67857 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:70586 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2026-2340 vdb-entryx_refsource_REDHATMitigationThird Party AdvisoryVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2447318 issue-trackingx_refsource_REDHATIssue TrackingThird Party Advisory
- https://bugzilla.samba.org/show_bug.cgi?id=15997 Issue TrackingVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-2340
- https://www.cve.org/CVERecord?id=CVE-2026-2340
Change history (0)
No recorded changes yet.