<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T02:41:49.668371+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-07423</id>
    <title>bdu:2026-07423</title>
    <updated>2026-10-03T02:41:49.809640+00:00</updated>
    <content>bdu:2026-07423</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-07423"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0651</id>
    <title>certfr-2026-avi-0651 — De multiples vulnérabilités ont été découvertes dans Samba. Certaines d'entre elles permettent à un attaquant de provoq…</title>
    <updated>2026-10-03T02:41:49.809678+00:00</updated>
    <content>certfr-2026-avi-0651</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0651"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-362261</id>
    <title>EUVD-2026-362261</title>
    <updated>2026-10-03T02:41:49.809698+00:00</updated>
    <content>EUVD-2026-362261</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-362261"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-3238</id>
    <title>fkie_cve-2026-3238</title>
    <updated>2026-10-03T02:41:49.809711+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in Samba’s WINS server component when running as an Active Directory Domain Controller. The WINS protocol handlers for certain request types did not properly validate incoming packets, allowing an unauthenticated remote attacker to trigger a NULL pointer dereference and crash the WINS service using specially crafted UDP packets.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-3238"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-gpff-px68-36rh</id>
    <title>GHSA-gpff-px68-36rh</title>
    <updated>2026-10-03T02:41:49.809743+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in Samba’s WINS server component when running as an Active Directory Domain Controller. The WINS protocol handlers for certain request types did not properly validate incoming packets, allowing an unauthenticated remote attacker to trigger a NULL pointer dereference and crash the WINS service using specially crafted UDP packets.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-gpff-px68-36rh"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-2574</id>
    <title>OESA-2026-2574 — samba security update</title>
    <updated>2026-10-03T02:41:49.809762+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP4: samba</p>
<p>Samba is a suite of programs for Linux and Unix to interoperate with Windows.

Security Fix(es):</p>
<p>A flaw was found in Samba&amp;apos;s certificate auto-enrollment Group Policy handling. When certificate auto-enrollment is enabled, Samba may retrieve a CA certificate over an unencrypted HTTP connection and install it into the local trust store without proper verification. An attacker with the ability to intercept or redirect network traffic could exploit this behavior to supply a malicious certificate authority certificate, potentially allowing interception or spoofing of trusted communications.(CVE-2026-3012)</p>
<p>[&amp;apos;-------- Forwarded Message --------&amp;apos;, &amp;apos;Date: Tue, 26 May 2026 14:29:50 +0200&amp;apos;, &amp;apos;Reply-To: Stefan Metzmacher &amp;lt;metze () samba org&amp;gt;&amp;apos;, &amp;apos;Release Announcements\n---------------------\n\nThis is a security release in order to address the following defects:\n\no CVE-2026-1933:   Missing access checks on reparse point operations\n\n                   On a share marked &amp;quot;read only = yes&amp;quot; and\n                   on file handles opened R/O users can set\n                   or delete the reparse point xattrs on files\n                   that the user has write-access in the file\n                   system for.&amp;apos;, &amp;apos;o CVE-2026-2340:   WORM vfs module does not block overwrites\n\n                   The WORM (Write-Once, Read Many) vfs module\n                   is supposed to lock write access to shared\n                   fil…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-2574"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-3238</id>
    <title>UBUNTU-CVE-2026-3238</title>
    <updated>2026-10-03T02:41:49.809816+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: samba, Ubuntu:Pro:16.04:LTS: samba, Ubuntu:Pro:18.04:LTS: samba, Ubuntu:Pro:20.04:LTS: samba, Ubuntu:22.04:LTS: samba, Ubuntu:24.04:LTS: samba, Ubuntu:25.10: samba, Ubuntu:26.04:LTS: samba</p>
<p>A flaw was found in Samba’s WINS server component when running as an Active Directory Domain Controller. The WINS protocol handlers for certain request types did not properly validate incoming packets, allowing an unauthenticated remote attacker to trigger a NULL pointer dereference and crash the WINS service using specially crafted UDP packets.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-3238"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1686</id>
    <title>WID-SEC-W-2026-1686 — Samba: Mehrere Schwachstellen</title>
    <updated>2026-10-03T02:41:49.809849+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Samba ausnutzen, um beliebigen Programmcode auszuführen, um einen Denial of Service Angriff durchzuführen, um Dateien zu manipulieren, und um Sicherheitsvorkehrungen zu umgehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1686"/>
  </entry>
</feed>
