Skip to content
Red HatCVE-2026-58218

Red Hat Samba: denial of service

Medium5.3CVE-2026-58218 · Published Jul 30, 2026

A flaw was found in Samba's internal DNS server where unauthenticated TKEY registration requests were added to the TKEY name cache before being rejected. A remote, unauthenticated attacker can exploit this behavior by sending a large number of TKEY requests with arbitrary names, exhausting the cache and evicting legitimate TKEY entries. This can prevent legitimate TSIG authentication for signed DNS queries, resulting in a denial of service.

Red Hat advisory

Affected versions

PackageAffectedFixed in
Red Hat Enterprise Linux 10
Product
all versionsNo fix yet
Red Hat Enterprise Linux 6
Product
all versionsNo fix yet
all versionsNo fix yet
Red Hat Enterprise Linux 7
Product
all versionsNo fix yet
Red Hat Enterprise Linux 8
Product
all versionsNo fix yet
Red Hat Enterprise Linux 9
Product
all versionsNo fix yet
Red Hat OpenShift Container Platform 4
Product
all versionsNo fix yet
Details and references

More Red Hat advisories

All Red Hat
Advisory
ansible-collection-redhat-leapp: information disclosure
Medium6.2Jul 30
ansible-collection-redhat-leapp.: insecure permissions
Medium5.5Jul 30
Red Hat Samba: out-of-bounds read
Medium5.3Jul 30
Red Hat Enterprise Linux 10: improper authorization
High8.8Jul 30
Red Hat Cost Management Metrics Operator: server-side request forgery
High7.6Jul 30
Red Hat Cost Management Metrics Operator: server-side request forgery
High7.6Jul 30

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.