CVE-2026-3012

high
Published 2026-05-27 ยท Modified 2026-06-03
CVSS v3
8.0
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
8.0

Description

Important: samba security update

Predictions

Exploit likelihood
77%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Red Hat Errata โ€” Red Hat Inc. ยท View original โ†— ยท Open-Errata-API

Description samba: group policy certificate enrollment uses http:// without validation Red Hat statement Red Hat Product Security has rated this vulnerability as Important severity. However, exploitation requires several specific non-default conditions to be met. The vulnerable code path is only reachable when Samba Group Policy processing is explicitly enabled using the ```apply group policies =โ€ฆ

Description

samba: group policy certificate enrollment uses http:// without validation

Red Hat statement

Red Hat Product Security has rated this vulnerability as Important severity. However, exploitation requires several specific non-default conditions to be met. The vulnerable code path is only reachable when Samba Group Policy processing is explicitly enabled using the ```apply group policies = yes``` configuration option and certificate auto-enrollment is configured through Group Policy. Hence, although the vulnerable code is present, it is not exploitable in default RHEL configurations. In addition, the attacker must have the ability to intercept or redirect adjacent-network HTTP traffic during certificate retrieval. Because exploitation depends on explicit administrative configuration changes and adjacent-network positioning, Red Hat assesses the attack complexity as High (AC:H).

CVSS v3: 8.0 (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N)

Errata / fixed releases

ProductPackageAdvisoryReleased
Red Hat Enterprise Linux 8samba-0:4.19.4-16.el8_10RHSA-2026:226442026-06-03T00:00:00Z
Red Hat Enterprise Linux 8samba-0:4.19.4-16.el8_10RHSA-2026:226442026-06-03T00:00:00Z

Package state

ProductPackageState
Red Hat Enterprise Linux 10sambaAffected
Red Hat Enterprise Linux 6sambaOut of support scope
Red Hat Enterprise Linux 6samba4Out of support scope
Red Hat Enterprise Linux 7sambaAffected
Red Hat Enterprise Linux 9sambaAffected
Red Hat OpenShift Container Platform 4rhcosAffected

Apply commands

bash fix
Apply RHSA-2026:22644 for Red Hat Enterprise Linux 8
yum update -y samba
# or:
dnf upgrade -y samba

Affected

VendorProductVersion
redhatRed Hat Enterprise Linux 10Affected
redhatRed Hat Enterprise Linux 7Affected
redhatRed Hat Enterprise Linux 9Affected
redhatRed Hat OpenShift Container Platform 4Affected

OS impact

suse SUSE Affected 1 release
VersionStatusFixed in
โ€” Affected โ€”
debian Debian Mixed 5 releases
VersionStatusFixed in
trixie Fixed 2:4.22.8+dfsg-0+deb13u2
sid Fixed 2:4.24.3+dfsg-1
forky Fixed 2:4.24.3+dfsg-1
bullseye Affected โ€”
bookworm Fixed 2:4.17.12+dfsg-0+deb12u4
almalinux AlmaLinux Fixed 1 release
VersionStatusFixed in
8 Fixed samba-pidl-4.19.4-16.el8_10.noarch.rpm
redhat Red Hat Fixed 1 release
VersionStatusFixed in
8 Fixed โ€”

References

CWEs

CWE-345

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.