<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T19:05:57.634833+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0939</id>
    <title>certfr-2026-avi-0939 — De multiples vulnérabilités ont été découvertes dans Samba. Certaines d'entre elles permettent à un attaquant de provoq…</title>
    <updated>2026-10-03T19:05:57.703310+00:00</updated>
    <content>certfr-2026-avi-0939</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0939"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-361741</id>
    <title>EUVD-2026-361741</title>
    <updated>2026-10-03T19:05:57.703352+00:00</updated>
    <content>EUVD-2026-361741</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-361741"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-58224</id>
    <title>fkie_cve-2026-58224</title>
    <updated>2026-10-03T19:05:57.703367+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in Samba's CTDB, the clustered database service used by Samba. Insufficient integrity validation of received CTDB protocol packets allows malformed packets containing invalid field lengths, improperly terminated strings, or inconsistent packet sizes to be processed without adequate bounds checking. A remote attacker with access to the CTDB private network may trigger a denial of service through process crashes or excessive memory consumption and, in limited cases, disclose adjacent memory contents.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-58224"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-ph76-744q-p8fh</id>
    <title>GHSA-ph76-744q-p8fh</title>
    <updated>2026-10-03T19:05:57.703400+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in Samba's CTDB, the clustered database service used by Samba. Insufficient integrity validation of received CTDB protocol packets allows malformed packets containing invalid field lengths, improperly terminated strings, or inconsistent packet sizes to be processed without adequate bounds checking. A remote attacker with access to the CTDB private network may trigger a denial of service through process crashes or excessive memory consumption and, in limited cases, disclose adjacent memory contents.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-ph76-744q-p8fh"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-3295</id>
    <title>OESA-2026-3295 — samba security update</title>
    <updated>2026-10-03T19:05:57.703419+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP4: samba</p>
<p>Samba is a suite of programs for Linux and Unix to interoperate with Windows.

Security Fix(es):</p>
<p>An out-of-bounds read flaw was found in Samba&amp;apos;s Kerberos Key Distribution Center&amp;apos;s (KDC) password change (kpasswd) service. When processing malformed ASN.1-encoded Kerberos password change request, Samba server miscalculates the structure size and attempts to read up to six bytes beyond the end of the allocated buffer. While this out-of-bounds read typically results in a harmless decryption failure, if the read hits unmapped memory, it causes the KDC process to crash. An authenticated attacker can send a specially crafted kpasswd request containing malformed ASN.1 data to trigger the out-of-bounds read, which may cause the KDC process to terminate, resulting in a denial of service.(CVE-2026-58216)</p>
<p>A flaw was found in Samba&amp;apos;s internal DNS server where unauthenticated TKEY registration requests were added to the TKEY name cache before being rejected. A remote, unauthenticated attacker can exploit this behavior by sending a large number of TKEY requests with arbitrary names, exhausting the cache and evicting legitimate TKEY entries. This can prevent legitimate TSIG authentication for signed DNS queries, resulting in a denial of service.(CVE-2026-58218)</p>
<p>Samba is an open-source implementation of file sharing and printing services for communication between Linux/Unix and Windows systems. CVE-2026-58221 is a security vulnerability in Samba affecting versions before 4…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-3295"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-58224</id>
    <title>UBUNTU-CVE-2026-58224</title>
    <updated>2026-10-03T19:05:57.703463+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: samba, Ubuntu:Pro:16.04:LTS: samba, Ubuntu:Pro:18.04:LTS: samba, Ubuntu:Pro:20.04:LTS: samba, Ubuntu:22.04:LTS: samba, Ubuntu:24.04:LTS: samba, Ubuntu:26.04:LTS: samba</p>
<p>A flaw was found in Samba's CTDB, the clustered database service used by Samba. Insufficient integrity validation of received CTDB protocol packets allows malformed packets containing invalid field lengths, improperly terminated strings, or inconsistent packet sizes to be processed without adequate bounds checking. A remote attacker with access to the CTDB private network may trigger a denial of service through process crashes or excessive memory consumption and, in limited cases, disclose adjacent memory contents.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-58224"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2549</id>
    <title>WID-SEC-W-2026-2549 — Samba: Mehrere Schwachstellen</title>
    <updated>2026-10-03T19:05:57.703501+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Samba ausnutzen, um vertrauliche Informationen offenzulegen, Sicherheitsmaßnahmen zu umgehen, einen Denial-of-Service-Zustand herbeizuführen oder Daten zu manipulieren.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2549"/>
  </entry>
</feed>
