Red Hat Product Errata RHSA-2026:25049 - Security Advisory Issued: 2026-06-10 Updated: 2026-06-10 RHSA-2026:25049 - Security Advisory Overview Updated Packages Synopsis Critical: samba security update Type/Severity Security Advisory: Critical Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for samba is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description Samba is an open-source implementation of the Server Message Block (SMB) protocol and the related Common Internet File System (CIFS) protocol, which allow PC-compatible machines to share files, printers, and various information. Security Fix(es): samba: Missing access check on reparse point operations (CVE-2026-1933) samba: vfs_worm does not block directory modification (CVE-2026-2340) samba: group policy certificate enrollment uses http:// without validation (CVE-2026-3012) samba: Samba: Remote Code Execution in printing subsystem via unescaped job description (CVE-2026-4480) ngtcp2: ngtcp2: Denial of service via stack buffer overflow during QUIC handshake (CVE-2026-40170) samba: Remote Code Execution in SAMR (CVE-2026-4408) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 9 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.8 x86_64 Red Hat Enterprise Linux for IBM z Systems 9 s390x Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.8 s390x Red Hat Enterprise Linux for Power, little endian 9 ppc64le Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.8 ppc64le Red Hat Enterprise Linux for ARM 64 9 aarch64 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.8 aarch64 Red Hat Enterprise Linux Resilient Storage for x86_64 9 x86_64 Red Hat Enterprise Linux Resilient Storage for x86_64 - Extended Update Support 9.8 x86_64 Red Hat Enterprise Linux Resilient Storage for IBM z Systems 9 s390x Red Hat Enterprise Linux Resilient Storage for Power, little endian 9 ppc64le Red Hat Enterprise Linux Resilient Storage for Power, little endian - Extended Update Support 9.8 ppc64le Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.8 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.8 x86_64 Red Hat CodeReady Linux Builder for x86_64 9 x86_64 Red Hat CodeReady Linux Builder for Power, little endian 9 ppc64le Red Hat CodeReady Linux Builder for ARM 64 9 aarch64 Red Hat CodeReady Linux Builder for IBM z Systems 9 s390x Red Hat Enterprise Linux Resilient Storage for IBM z Systems - Extended Update Support 9.8 s390x Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support 9.8 x86_64 Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support 9.8 ppc64le Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support 9.8 s390x Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support 9.8 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.8 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.8 s390x Red Hat Enterprise Linux Resilient Storage for x86_64 - 4 years of updates 9.8 x86_64 Red Hat Enterprise Linux Resilient Storage for Power, little endian - 4 years of updates 9.8 ppc64le Red Hat Enterprise Linux Resilient Storage for IBM z Systems - 4 years of updates 9.8 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.8 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.8 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.8 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.8 s390x Red Hat Enterprise Linux Resilient Storage for Power, little endian - Extended Life Cycle 9.8 ppc64le Red Hat Enterprise Linux Resilient Storage for IBM z Systems - Extended Life Cycle 9.8 s390x Red Hat Enterprise Linux Resilient Storage for x86_64 - Extended Life Cycle 9.8 x86_64 Fixes BZ - 2447317 - CVE-2026-1933 samba: Missing access check on reparse point operations BZ - 2447318 - CVE-2026-2340 samba: vfs_worm does not block directory modification BZ - 2447319 - CVE-2026-3012 samba: group policy certificate enrollment uses http:// without validation BZ - 2452232 - CVE-2026-4480 samba: Samba: Remote Code Execution in printing subsystem via unescaped job description BZ - 2459061 - CVE-2026-40170 ngtcp2: ngtcp2: Denial of service via stack buffer overflow during QUIC handshake BZ - 2479762 - CVE-2026-4408 samba: Remote Code Execution in SAMR CVEs CVE-2026-1933 CVE-2026-2340 CVE-2026-3012 CVE-2026-4408 CVE-2026-4480 CVE-2026-40170 References https://access.redhat.com/security/updates/classification/#critical Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 9 SRPM samba-4.23.5-10.el9_8.src.rpm SHA-256: 1dacfe5d1b03043890b89552d0ed47bbf1c71fed9533f1e3560014b3548d5381 x86_64 ctdb-debuginfo-4.23.5-10.el9_8.i686.rpm SHA-256: c01efe355cfeeea226a04cb58d6c2f06236d33354a9190786b356975e9a3c1a6 ctdb-debuginfo-4.23.5-10.el9_8.x86_64.rpm SHA-256: e291b9ab49cf581aa718a4604bf5ce87af3805bc00f0949dcc01e8a46c19822b ctdb-debuginfo-4.23.5-10.el9_8.x86_64.rpm SHA-256: e291b9ab49cf581aa718a4604bf5ce87af3805bc00f0949dcc01e8a46c19822b ldb-tools-4.23.5-10.el9_8.x86_64.rpm SHA-256: 279c050914e85bd38e5804abe233bd80e3dd90af431b3445adada5c9b2e929df ldb-tools-debuginfo-4.23.5-10.el9_8.i686.rpm SHA-256: 1ce1c0bbd1e73278b6003b2b4470125333c36d31ecc583b069938372b761b870 ldb-tools-debuginfo-4.23.5-10.el9_8.x86_64.rpm SHA-256: df607581329fd1b0b11716de144da1657d72a61ad53e963fc7a95d527375b759 ldb-tools-debuginfo-4.23.5-10.el9_8.x86_64.rpm SHA-256: df607581329fd1b0b11716de144da1657d72a61ad53e963fc7a95d527375b759 libldb-4.23.5-10.el9_8.i686.rpm SHA-256: 832262a9d41afe3b3663d7ab8edcae078022c3482ab26b9cd8ccb197b123682b libldb-4.23.5-10.el9_8.x86_64.rpm SHA-256: 448c60b183d5ee01bfe1583e92197ad5d15e13c9e1a31b316e4a9531d1f6e7d8 libldb-debuginfo-4.23.5-10.el9_8.i686.rpm SHA-256: eb834d8c57c39166a9d35a83199515c37765a50752040f1b296d6260e5a005cb libldb-debuginfo-4.23.5-10.el9_8.x86_64.rpm SHA-256: 4031d51195699c68355430fd45ca630409f38a4bb9455350b4adb94bf8a1f777 libldb-debuginfo-4.23.5-10.el9_8.x86_64.rpm SHA-256: 4031d51195699c68355430fd45ca630409f38a4bb9455350b4adb94bf8a1f777 libnetapi-4.23.5-10.el9_8.i686.rpm SHA-256: 1113b2ef422f3ad885623463252a02e6487d094539d353fabb35e28d87c2456e libnetapi-4.23.5-10.el9_8.x86_64.rpm SHA-256: 3b22c24d9d73cda66ffdb588a2a9e61cc72c1138896dc21e54b2948f8fc80284 libnetapi-debuginfo-4.23.5-10.el9_8.i686.rpm SHA-256: 9c73e5ca4c7e69407e85bf4d552b945ed1de5817a9957f7e5c7c1f6d5ebf6a3e libnetapi-debuginfo-4.23.5-10.el9_8.x86_64.rpm SHA-256: 16e41b654bab032d075ea585ed422598d46ac9682a6457d469ac587d47f28e13 libnetapi-debuginfo-4.23.5-10.el9_8.x86_64.rpm SHA-256: 16e41b654bab032d075ea585ed422598d46ac9682a6457d469ac587d47f28e13 libsmbclient-4.23.5-10.el9_8.i686.rpm SHA-256: ce8dcfb4dd64f248c10b6806a9cece826da4fa07f115fbaf11cbbcb5046a18c0 libsmbclient-4.23.5-10.el9_8.x86_64.rpm SHA-256: c1e511948d4051903a8a4a6ab56cd5d5d58c40a1af1d3ec8e31dbdeea16098a7 libsmbclient-debuginfo-4.23.5-10.el9_8.i686.rpm SHA-256: d84baeee6be2d1915bd6525275a0b576c493bdbaa7f02b3965115f95d83f1aac libsmbclient-debuginfo-4.23.5-10.el9_8.x86_64.rpm SHA-256: 1398b8940e10faafa27c054ec6a391011da17c2385ff750a99a170e2d6f2aedc libsmbclient-debuginfo-4.23.5-10.el9_8.x86_64.rpm SHA-256: 1398b8940e10faafa27c054ec6a391011da17c2385ff750a99a170e2d6f2aedc libwbclient-4.23.5-10.el9_8.i686.rpm SHA-256: c23ad51c0173613f2ee8153e20c7fb2a92d8802cc6d73ab58cb0e7eb8a100009 libwbclient-4.23.5-10.el9_8.x86_64.rpm SHA-256: f3d9f61b86a1b84397ba4553135efeea179a6ade0866e6aa09e5d9482c5c0d76 libwbclient-debuginfo-4.23.5-10.el9_8.i686.rpm SHA-256: a1d57c43967a7b354f1ef9512b70ed2046a0c2cf966acc3c889cec6676ad4553 libwbclient-debuginfo-4.23.5-10.el9_8.x86_64.rpm SHA-256: 678d91c355933399f9474d3abf50dfb9af0efbdc9c28f646237e021b50fd8b01 libwbclient-debuginfo-4.23.5-10.el9_8.x86_64.rpm SHA-256: 678d91c355933399f9474d3abf50dfb9af0efbdc9c28f646237e021b50fd8b01 python3-ldb-4.23.5-10.el9_8.i686.rpm SHA-256: b53a663fbb95dc6cdc220c3d7dd2e4d2e2c433ab4c23b642ab7355d8c1c07be2 python3-ldb-4.23.5-10.el9_8.x86_64.rpm SHA-256: 2c0f6e0ff727c225abfe71b7a646ab86264f335217a6297a69a9211cf56829d7 python3-ldb-debuginfo-4.23.5-10.el9_8.i686.rpm SHA-256: 87b1dab0e7e897355473c1abbeb4ba627113d9d231ccbef12c0c1185855ad451 python3-ldb-debuginfo-4.23.5-10.el9_8.x86_64.rpm SHA-256: 501cc17e4ada449437b5f692d032628a1e36aa691360f770ef8db00a2f8b40c3 python3-ldb-debuginfo-4.23.5-10.el9_8.x86_64.rpm SHA-256: 501cc17e4ada449437b5f692d032628a1e36aa691360f770ef8db00a2f8b40c3 python3-samba-4.23.5-10.el9_8.i686.rpm SHA-256: 86f1ef9a61e5ac86390a2de8d12cc0f17e31a720b73478b5ee609235aba3c3ba python3-samba-4.23.5-10.el9_8.x86_64.rpm SHA-256: 3db9041dd49e45608b62a08057a3ad475d771ba353980840d0401284d5f7732a python3-samba-dc-4.23.5-10.el9_8.x86_64.rpm SHA-256: 13f000aee2f814b6406cff3f9f2bfb4c650bc40e2319047b1c121e48f2c4b783 python3-samba-dc-debuginfo-4.23.5-10.el9_8.i686.rpm SHA-256: ec0e01aa77a3459c49c021e9d87178654a1a4cdb84876e28209692ed9b054850 python3-samba-dc-debuginfo-4.23.5-10.el9_8.x86_64.rpm SHA-256: 38cdb5cd4de1f864fb30943c32e0a4615415debe0d3d1ebd79fd01f5b83622a6 python3-samba-dc-debuginfo-4.23.5-10.el9_8.x86_64.rpm SHA-256: 38cdb5cd4de1f8
This critical Samba update addresses multiple vulnerabilities, including a remote code execution flaw in the printing subsystem via unescaped job descriptions (CVE-2026-4480) and another in the SAMR protocol (CVE-2026-4408), alongside other high-severity issues like missing access checks on reparse points (CVE-2026-1933, CVSS 7.1) and insecure group policy certificate enrollment (CVE-2026-3012, CVSS 8.0). Specific affected version ranges include Samba 4.1.0 through 4.2.1 for CVE-2026-1933 and 4.16.0 through 4.20.x for CVE-2026-3012, with fixes provided in versions 4.2.2 and 4.21.0 respectively. The advisory applies to Red Hat Enterprise Linux 9 and related variants, and administrators should apply the referenced patches immediately.