samba: TSIG packet with crafted name compression can crash DNS server
Published Jul 28, 2026
7.5
HIGHCVSS 3.1
Description
A flaw was found in Samba's internal DNS server when processing TSIG-signed DNS packets containing compressed names. Incorrect size calculations while determining the portion of the DNS packet covered by the TSIG signature can result in an integer underflow, leading to an out-of-bounds memory write during packet processing. A remote attacker can send a specially crafted TSIG-signed DNS packet to cause the DNS server to terminate unexpectedly.
Affected products
No data.
No data.
No data.
Red Hat Enterprise Linux 10
samba
Not affected
Red Hat Enterprise Linux 6
samba
Not affected
Red Hat Enterprise Linux 6
samba4
Not affected
Red Hat Enterprise Linux 7
samba
Not affected
Red Hat Enterprise Linux 8
samba
Not affected
Red Hat Enterprise Linux 9
samba
Not affected
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-8
Not affected
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-9
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | samba | Not affected | n/a |
| Red Hat Enterprise Linux 6 | samba | Not affected | n/a |
| Red Hat Enterprise Linux 6 | samba4 | Not affected | n/a |
| Red Hat Enterprise Linux 7 | samba | Not affected | n/a |
| Red Hat Enterprise Linux 8 | samba | Not affected | n/a |
| Red Hat Enterprise Linux 9 | samba | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-8 | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-9 | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Product Security evaluates this vulnerability as having an Important impact for Samba deployments operating as an Active Directory Domain Controller (AD DC) using the internal DNS server engine. ``` Red Hat Enterprise Linux (RHEL) Context: Default installations of Red Hat Enterprise Linux (RHEL) are not affected. RHEL does not ship or support the Samba Active Directory Domain Controller (AD DC) role or its internal DNS server component where this vulnerability resides. ``` ``` Additionally, Samba AD DC deployments that use the external BIND9 DLZ plugin instead of the internal DNS server engine are completely unaffected by this issue. ```
References (6)
- https://access.redhat.com/security/cve/CVE-2026-6949 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2502730 Issue Tracking
- https://bugzilla.samba.org/show_bug.cgi?id=16083
- https://nvd.nist.gov/vuln/detail/CVE-2026-6949
- https://www.cve.org/CVERecord?id=CVE-2026-6949
- https://www.samba.org/samba/security/CVE-2026-6949.html
Change history (0)
No recorded changes yet.