Skip to content
Red HatCVE-2026-58224

Red Hat Samba: denial of service

Medium6.5CVE-2026-58224 · Published Aug 14, 2026 · updated Sep 23, 2026

A flaw was found in Samba's CTDB, the clustered database service used by Samba. Insufficient integrity validation of received CTDB protocol packets allows malformed packets containing invalid field lengths, improperly terminated strings, or inconsistent packet sizes to be processed without adequate bounds checking. A remote attacker with access to the CTDB private network may trigger a denial of service through process crashes or excessive memory consumption and, in limited cases, disclose adjacent memory contents.

Red Hat advisory

Affected versions

PackageAffectedFixed in
Red Hat Enterprise Linux 10
Product
all versionsNo fix yet
Red Hat Enterprise Linux 6
Product
all versionsNo fix yet
all versionsNo fix yet
all versionsNo fix yet
Red Hat Enterprise Linux 7
Product
all versionsNo fix yet
Red Hat Enterprise Linux 8
Product
all versionsNo fix yet
Red Hat Enterprise Linux 9
Product
all versionsNo fix yet
Red Hat OpenShift Container Platform 4
Product
all versionsNo fix yet
all versionsNo fix yet
Details and references

More Red Hat advisories

All Red Hat
Advisory
Red Hat Quay: attacker could inject LDAP filter metacharacters
Medium4.8Aug 14
Red Hat Quay: information disclosure
Medium5.3Aug 14
Red Hat Quay.: path traversal
Medium6.5Aug 14
Red Hat Quay: improper signature check
Medium5.9Aug 14
Red Hat Quay: information disclosure
Medium5.9Aug 14
Red Hat Quay: server-side request forgery
Medium4.2Aug 14

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.