Samba是Samba组织开源的一个适用于 Linux 和 Unix 的标准 Windows 互操作性程序套件。 Samba存在权限许可和访问控制问题漏洞,该漏洞源于samba的pam_winbind在mkhomedir启用时未验证目标主目录路径不是关键系统目录(如/),可能导致非特权用户通过sudo委托触发/目录所有权变更,从而导致严重拒绝服务(SSH、sudo和包管理器故障)。以下版本受到影响:Red Hat Enterprise Linux 10版本、Red Hat Enterprise Linux
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 6 | any |
unknown |
| Red Hat | Red Hat Enterprise Linux 7 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 8 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 9 | any |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 6 | - |
cpe:/o:redhat:enterprise_linux:6
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-12382 | 8.2 HIGH | Aap-gateway: missing requestheaderstoremove allows mtls bypass via subject header spoofing |
| CVE-2026-15809 | 7.8 HIGH | Github.com/cri-o/cri-o: fix bypass for cve-2022-4318 — /etc/passwd injection via home env |
| CVE-2026-14251 | 7.7 HIGH | Gitops-operator: gitops-operator: missing allowednamespace check in reconcilerhook for clu |
No comments yet