Skip to content
Red HatCVE-2026-15779

Red Hat samba: denial of service

Medium6.1CVE-2026-15779 · Published Jul 15, 2026

A flaw was found in samba's pam_winbind. When mkhomedir is enabled, pam_winbind chowns the target account's home directory without validating the path is not a critical system directory such as /. On affected systems, accounts with / as their home directory (a common default for system accounts) can have this triggered not only by root, but by a non-root user holding a narrow sudo delegation to run commands as that account, causing ownership of / to change and resulting in severe denial of service (SSH, sudo, and package-manager failures). The change does not grant write access to / (which ships with restrictive 0555 permissions on RHEL), so the impact is availability loss rather than further privilege escalation.

Red Hat advisory

Affected versions

PackageAffectedFixed in
Red Hat Enterprise Linux 10
Product
all versionsNo fix yet
Red Hat Enterprise Linux 6
Product
all versionsNo fix yet
Red Hat Enterprise Linux 7
Product
all versionsNo fix yet
Red Hat Enterprise Linux 8
Product
all versionsNo fix yet
Red Hat Enterprise Linux 9
Product
all versionsNo fix yet
Details and references

More Red Hat advisories

All Red Hat
Advisory
Red Hat AAP Gateway Envoy proxy configuration: authentication bypass by spoofing
High8.2Jul 15
Red Hat CRI-O: format string
High7.8Jul 15
Red Hat OpenShift GitOps: denial of service
High7.7Jul 15
A flaw was found in libsoup's WebSocket implementation
High7.5Jul 14
Red Hat libsoup: denial of service
High7.5Jul 14
Red Hat libsoup: denial of service
Medium5.9Jul 14

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.