Back

HIGH

samba: TSIG packet with crafted name compression can crash DNS server

Published Jul 28, 2026

Description

A flaw was found in Samba's internal DNS server when processing TSIG-signed DNS packets containing compressed names. Incorrect size calculations while determining the portion of the DNS packet covered by the TSIG signature can result in an integer underflow, leading to an out-of-bounds memory write during packet processing. A remote attacker can send a specially crafted TSIG-signed DNS packet to cause the DNS server to terminate unexpectedly.

Affected products

Remediation

Red Hat statement

Red Hat Product Security evaluates this vulnerability as having an Important impact for Samba deployments operating as an Active Directory Domain Controller (AD DC) using the internal DNS server engine. ``` Red Hat Enterprise Linux (RHEL) Context: Default installations of Red Hat Enterprise Linux (RHEL) are not affected. RHEL does not ship or support the Samba Active Directory Domain Controller (AD DC) role or its internal DNS server component where this vulnerability resides. ``` ``` Additionally, Samba AD DC deployments that use the external BIND9 DLZ plugin instead of the internal DNS server engine are completely unaffected by this issue. ```

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status n/a
Assigner n/a
Published Jul 28, 2026
Updated n/a
Reserved n/a
NVD
Status n/a
Modified n/a
Red Hat
Severity Important
Public date Jul 28, 2026
ENISA EUVD
Assigner n/a
Published n/a
Updated n/a
Exploited since n/a
Link n/a