CVE-2026-40170
Samba is an open-source implementation of the Server Message Block (SMB) protocol and the related Common Internet File System (CIFS) protocol, which allow PC-compatible machines to share files, printers, and various information.
Security Fix(es):
- samba: Missing access check on reparse point operations (CVE-2026-1933)
- samba: vfs_worm does not block directory modification (CVE-2026-2340)
- samba: group policy certificate enrollment uses http:// without validation (CVE-2026-3012)
- samba: Samba: Remote Code Execution in printing subsystem via unescaped job description (CVE-2026-4480)
- ngtcp2: ngtcp2: Denial of service via stack buffer overflow during QUIC handshake (CVE-2026-40170)
- samba: Remote Code Execution in SAMR (CVE-2026-4408)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://access.redhat.com/errata/RHSA-2026:25049, https://access.redhat.com/security/cve/CVE-2026-1933, https://access.redhat.com/security/cve/CVE-2026-2340, https://access.redhat.com/security/cve/CVE-2026-3012, https://access.redhat.com/security/cve/CVE-2026-40170, https://access.redhat.com/security/cve/CVE-2026-4408, https://access.redhat.com/security/cve/CVE-2026-4480
