Red Hat Product Errata RHSA-2026:22644 - Security Advisory Issued: 2026-06-02 Updated: 2026-06-02 RHSA-2026:22644 - Security Advisory Overview Updated Packages Synopsis Important: samba security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for samba is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description Samba is an open-source implementation of the Server Message Block (SMB) protocol and the related Common Internet File System (CIFS) protocol, which allow PC-compatible machines to share files, printers, and various information. Security Fix(es): samba: group policy certificate enrollment uses http:// without validation (CVE-2026-3012) samba: Samba: Remote Code Execution in printing subsystem via unescaped job description (CVE-2026-4480) samba: Remote Code Execution in SAMR (CVE-2026-4408) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 8 x86_64 Red Hat Enterprise Linux for IBM z Systems 8 s390x Red Hat Enterprise Linux for Power, little endian 8 ppc64le Red Hat Enterprise Linux for ARM 64 8 aarch64 Red Hat CodeReady Linux Builder for x86_64 8 x86_64 Red Hat CodeReady Linux Builder for Power, little endian 8 ppc64le Red Hat CodeReady Linux Builder for ARM 64 8 aarch64 Red Hat CodeReady Linux Builder for IBM z Systems 8 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 8.10 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 8.10 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 8.10 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 8.10 s390x Fixes BZ - 2447319 - CVE-2026-3012 samba: group policy certificate enrollment uses http:// without validation BZ - 2452232 - CVE-2026-4480 samba: Samba: Remote Code Execution in printing subsystem via unescaped job description BZ - 2479762 - CVE-2026-4408 samba: Remote Code Execution in SAMR CVEs CVE-2026-3012 CVE-2026-4408 CVE-2026-4480 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 8 SRPM samba-4.19.4-16.el8_10.src.rpm SHA-256: 1d5e50d6d71663502af61d34f73cef2067f4a335a6d274d1a9c05294c4dbd9d6 x86_64 ctdb-4.19.4-16.el8_10.x86_64.rpm SHA-256: 672b5b026fb6e05b0a0f3836d2160539b9f3ac8b5f7f1ee0fdb6c18cc39df77a ctdb-debuginfo-4.19.4-16.el8_10.i686.rpm SHA-256: 206c63a21bf4333738e324c5e5fc51edce3d326212bac20d98ea59e02b92ff63 ctdb-debuginfo-4.19.4-16.el8_10.x86_64.rpm SHA-256: b69dac79a4fb647f3313ed0d1659ba7b090458ade9ceac331fd39329822889c2 ctdb-debuginfo-4.19.4-16.el8_10.x86_64.rpm SHA-256: b69dac79a4fb647f3313ed0d1659ba7b090458ade9ceac331fd39329822889c2 libnetapi-4.19.4-16.el8_10.i686.rpm SHA-256: c06719803f6056426df6cf1c7a8c613c3d79538cfee5c76c8b7bb98c6b7abb70 libnetapi-4.19.4-16.el8_10.x86_64.rpm SHA-256: 84d136d4e59b8898819234ced8066703848ebe1152ee949f0b2ed748f28a81cf libnetapi-debuginfo-4.19.4-16.el8_10.i686.rpm SHA-256: 16112788f1ab95d0e8d7ee4bb4d73dd173536dadd42b7f859c59bba6db97cdd6 libnetapi-debuginfo-4.19.4-16.el8_10.x86_64.rpm SHA-256: 19023196d15eea9b2c5d34cde3b8f5f45303a55a28f48dec5ac46e3f5b37458a libnetapi-debuginfo-4.19.4-16.el8_10.x86_64.rpm SHA-256: 19023196d15eea9b2c5d34cde3b8f5f45303a55a28f48dec5ac46e3f5b37458a libsmbclient-4.19.4-16.el8_10.i686.rpm SHA-256: aaf32c6a7d982a70e6d1baa9285c206dbf976b0b242dd66110459228574bbc89 libsmbclient-4.19.4-16.el8_10.x86_64.rpm SHA-256: 261a1cf24c697267cebd86f375f0e0a6755e671f59830daa52439765843ca545 libsmbclient-debuginfo-4.19.4-16.el8_10.i686.rpm SHA-256: bbb7a8a0514f3f9ad0d9726a1230a6cb28cba1e9182c1fc337ff78c1c05296da libsmbclient-debuginfo-4.19.4-16.el8_10.x86_64.rpm SHA-256: ee4a4be72f0a6416e910a298844002eb3cc4ac172abfab8151413cf3afead1b8 libsmbclient-debuginfo-4.19.4-16.el8_10.x86_64.rpm SHA-256: ee4a4be72f0a6416e910a298844002eb3cc4ac172abfab8151413cf3afead1b8 libwbclient-4.19.4-16.el8_10.i686.rpm SHA-256: 94a9647092a0991954f236010a662f3c2c59d2f5dc49abda6588a164aa16dcce libwbclient-4.19.4-16.el8_10.x86_64.rpm SHA-256: 02f94780f62c734eaf2fbc12dc32c4bd7daa86d0f4cc53398d5497d6163c334b libwbclient-debuginfo-4.19.4-16.el8_10.i686.rpm SHA-256: 51837c41aa653f337d93d41cf7d13bd90ea96f10b95cf75ce0c8552d6fe1d9ad libwbclient-debuginfo-4.19.4-16.el8_10.x86_64.rpm SHA-256: 71134b68443d7398145f46e38713b73e722f2164c7ea56a76f68037adb9257b4 libwbclient-debuginfo-4.19.4-16.el8_10.x86_64.rpm SHA-256: 71134b68443d7398145f46e38713b73e722f2164c7ea56a76f68037adb9257b4 python3-samba-4.19.4-16.el8_10.i686.rpm SHA-256: 8ab784d1464a229646909f9c9e98ba0fdfe38f3e7ba01e0dbe38d80d9bab4445 python3-samba-4.19.4-16.el8_10.x86_64.rpm SHA-256: e473faceab98f4c302c66a7338a79f8e6732cc0a97b7b8da78ccb1881b4366be python3-samba-dc-4.19.4-16.el8_10.x86_64.rpm SHA-256: 5e81a72bdd17ebb6f247deb7ffe0b66c21d55748bd74623ce5ca1418eaf0d811 python3-samba-dc-debuginfo-4.19.4-16.el8_10.i686.rpm SHA-256: e56a0275fdb32aca63cefab1e4fc04260b1dae17ca3de640a91448c14a4e1c25 python3-samba-dc-debuginfo-4.19.4-16.el8_10.x86_64.rpm SHA-256: 4a72ce6a2ca9ad9b67d804793e45d29ed460274aefa944ce7272caf5d571e91b python3-samba-dc-debuginfo-4.19.4-16.el8_10.x86_64.rpm SHA-256: 4a72ce6a2ca9ad9b67d804793e45d29ed460274aefa944ce7272caf5d571e91b python3-samba-debuginfo-4.19.4-16.el8_10.i686.rpm SHA-256: 4e8f4e165a3fdd86cb7cb9a8cf6db03bb52e44cf018274c902ccd603be8356fe python3-samba-debuginfo-4.19.4-16.el8_10.x86_64.rpm SHA-256: b93ead81e00369008f7b65e95b30498489caf434b91c376e8fd8e15e1c93fe2a python3-samba-debuginfo-4.19.4-16.el8_10.x86_64.rpm SHA-256: b93ead81e00369008f7b65e95b30498489caf434b91c376e8fd8e15e1c93fe2a python3-samba-test-4.19.4-16.el8_10.x86_64.rpm SHA-256: 04d51ffac329da0f9868e89afa5891116586361bf59dbbcd23844acf2fc8c41c samba-4.19.4-16.el8_10.x86_64.rpm SHA-256: 199cd044a4ee233558503ace4004cccbea9ea3b293dbd4e902635b1bf5ee0c8b samba-client-4.19.4-16.el8_10.x86_64.rpm SHA-256: 6d7ce33f82cd00d5cafacb24de7eb8f3ed086011ff0e501a33b2c88dcd0ab4a2 samba-client-debuginfo-4.19.4-16.el8_10.i686.rpm SHA-256: 0772605a3bc964487275ea9749d39a8112786721be27ab6d0d6db87d64386000 samba-client-debuginfo-4.19.4-16.el8_10.x86_64.rpm SHA-256: dabd6b5947db2efb0ccbd96ada8684b843dec0866d2ac3b822758c49e6cabef9 samba-client-debuginfo-4.19.4-16.el8_10.x86_64.rpm SHA-256: dabd6b5947db2efb0ccbd96ada8684b843dec0866d2ac3b822758c49e6cabef9 samba-client-libs-4.19.4-16.el8_10.i686.rpm SHA-256: 4d4f9782ded9e4f0260bd350302fe660d6f5da5a558812cc9484dbbbcc7af8ed samba-client-libs-4.19.4-16.el8_10.x86_64.rpm SHA-256: 6224fec896d8d3e611ef7d115590778386d50ad7d0d7af027f2cb72a83cda9ef samba-client-libs-debuginfo-4.19.4-16.el8_10.i686.rpm SHA-256: 6605a7f3916704398066d6c66ea2d0de0332c7c9f680b4b1ac6901a7628c261a samba-client-libs-debuginfo-4.19.4-16.el8_10.x86_64.rpm SHA-256: 40518d9674b0381c4f3671d8eb8d3b3524fae4db82e5981f4aed38393e27ff9a samba-client-libs-debuginfo-4.19.4-16.el8_10.x86_64.rpm SHA-256: 40518d9674b0381c4f3671d8eb8d3b3524fae4db82e5981f4aed38393e27ff9a samba-common-4.19.4-16.el8_10.noarch.rpm SHA-256: 3e0893e2a80e553acdcbbc0e26f362e7bd8304932262e3149b23252d1a177edd samba-common-libs-4.19.4-16.el8_10.i686.rpm SHA-256: 6028237f2774a22326e72070db0658ddfea92222af7ebab971d2a3321792d4a6 samba-common-libs-4.19.4-16.el8_10.x86_64.rpm SHA-256: 227e0c7247cb832fa744641d45e805d12d00b28d25b1ca3a60ba44509e30f979 samba-common-libs-debuginfo-4.19.4-16.el8_10.i686.rpm SHA-256: aa7f512f41740a40e545f4c08995c98287f078dd2950c98da394c5804cd7244a samba-common-libs-debuginfo-4.19.4-16.el8_10.x86_64.rpm SHA-256: a7d3710f33b1a5e87ff1f8b1bf5460c1d584fdedba8574bcb05e4e5ddb38e968 samba-common-libs-debuginfo-4.19.4-16.el8_10.x86_64.rpm SHA-256: a7d3710f33b1a5e87ff1f8b1bf5460c1d584fdedba8574bcb05e4e5ddb38e968 samba-common-tools-4.19.4-16.el8_10.x86_64.rpm SHA-256: 66e3b79210ae507ec41c66340e7db4b435e57cc6d90453a03d439157cf38fe65 samba-common-tools-debuginfo-4.19.4-16.el8_10.i686.rpm SHA-256: 65e0975316da5954817b546c6f5e0364e85cafa8341ce8af04f2c7e67f06c440 samba-common-tools-debuginfo-4.19.4-16.el8_10.x86_64.rpm SHA-256: c9a9d15906d16d1bf3235b3db7f31f89690d7a29c9a3384e9d86ac26bec0d0b7 samba-common-tools-debuginfo-4.19.4-16.el8_10.x86_64.rpm SHA-256: c9a9d15906d16d1bf3235b3db7f31f89690d7a29c9a3384e9d86ac26bec0d0b7 samba-dc-libs-4.19.4-16.el8_10.i686.rpm SHA-256: 9a7de375f92046ce4da0f0a7fa132308d3ab0b2bb9c6ddd7791ff259b5de6692 samba-dc-libs-4.19.4-16.el8_10.x86_64.rpm SHA-256: 944d6b1a6155c4f462522fa9f04bab8262a3c3cb4d88f1dd76af9122dac97e15 samba-dc-libs-debuginfo-4.19.4-16.el8_10.i686.rpm SHA-256: 5dc97095d47c2eb0bf8fc41e509fd47f12c3446c18c251f5ed763f21a8fc6338 samba-dc-libs-debuginfo-4.19.4-16.el8_10.x86_64.rpm SHA-256: 6c6f027aa9a35db0c14f482ad024877aa74e95373908a3fbff21826361af9195 samba-dc-libs-debuginfo-4.19.4-16.el8_10.x86_64.rpm SHA-256: 6c6f027aa9a35db0c14f482ad024877aa74e95373908a3fbff21826361af9195 samba-dcerpc-4.19.4-16.el8_10.x86_64.rpm SHA-256: c2a9af711afe8d69f03976f1f10a0e965b2edc8edb8d421da3968ec532cb7ef7 samba-dcerpc-debuginfo-4.19.4-16.el8_10.i686.rpm SHA-256: ebd2e8f54a0eb76ab4f9c4309f0324265a6c4ee8c30f06ac844b3e13852c4eff samba-dcerpc-debuginfo-4.19.4-16.el8_10.x86_64.rpm SHA-256: 9ab1bd1e4c587c70f7fed229743374dca15bd3114a7904bbb6d65cf57cdaac7a samba-dcerpc-debuginfo-4.19.4-16.el8_10.x86_64.rpm SHA-256: 9ab1bd1e4c587c70f7fed229743374dca15bd3114
This Red Hat security advisory addresses three high-severity vulnerabilities in Samba, including a critical (CVSS 9.0) remote code execution flaw in the SAMR protocol (CVE-2026-4408) and a high-severity (CVSS 8.5) RCE in the printing subsystem via unescaped job descriptions (CVE-2026-4480). The printing subsystem RCE affects Samba versions 4.1.0 through 4.2.0. Red Hat has released a security update for Samba on RHEL 8, with the fixed package version being `samba-4.19.4-16.el8_10`.