Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-15779— Samba-winbind: samba: pam_winbind mkhomedir chowns critical system paths without validation

Quick assessment

Affected
Red Hat Red Hat Enterprise Linux 10
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Samba是Samba组织开源的一个适用于 Linux 和 Unix 的标准 Windows 互操作性程序套件。 Samba存在权限许可和访问控制问题漏洞,该漏洞源于samba的pam_winbind在mkhomedir启用时未验证目标主目录路径不是关键系统目录(如/),可能导致非特权用户通过sudo委托触发/目录所有权变更,从而导致严重拒绝服务(SSH、sudo和包管理器故障)。以下版本受到影响:Red Hat Enterprise Linux 10版本、Red Hat Enterprise Linux

CVSS 6.1 · Medium EPSS 0.10% · P1

Affected Version Matrix 5

Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-15779

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Samba-winbind: samba: pam_winbind mkhomedir chowns critical system paths without validation
Source: CVE Program / CVE List V5
Vulnerability Description
A flaw was found in samba's pam_winbind. When mkhomedir is enabled, pam_winbind chowns the target account's home directory without validating the path is not a critical system directory such as /. On affected systems, accounts with / as their home directory (a common default for system accounts) can have this triggered not only by root, but by a non-root user holding a narrow sudo delegation to run commands as that account, causing ownership of / to change and resulting in severe denial of service (SSH, sudo, and package-manager failures). The change does not grant write access to / (which ships with restrictive 0555 permissions on RHEL), so the impact is availability loss rather than further privilege escalation.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
关键资源的不正确权限授予
Source: CVE Program / CVE List V5
Vulnerability Title
Samba 权限许可和访问控制问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Samba是Samba组织开源的一个适用于 Linux 和 Unix 的标准 Windows 互操作性程序套件。 Samba存在权限许可和访问控制问题漏洞,该漏洞源于samba的pam_winbind在mkhomedir启用时未验证目标主目录路径不是关键系统目录(如/),可能导致非特权用户通过sudo委托触发/目录所有权变更,从而导致严重拒绝服务(SSH、sudo和包管理器故障)。以下版本受到影响:Red Hat Enterprise Linux 10版本、Red Hat Enterprise Linux
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Red Hat Red Hat Enterprise Linux 10 - cpe:/o:redhat:enterprise_linux:10
Red Hat Red Hat Enterprise Linux 6 - cpe:/o:redhat:enterprise_linux:6
Red Hat Red Hat Enterprise Linux 7 - cpe:/o:redhat:enterprise_linux:7
Red Hat Red Hat Enterprise Linux 8 - cpe:/o:redhat:enterprise_linux:8
Red Hat Red Hat Enterprise Linux 9 - cpe:/o:redhat:enterprise_linux:9

II. Public POCs for CVE-2026-15779

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-15779

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-15779 (3)

Vendor Advisories for CVE-2026-15779 (2)

Same Patch Batch · Red Hat · 2026-07-15 · 4 CVEs total

CVE-2026-12382 8.2 HIGH Aap-gateway: missing requestheaderstoremove allows mtls bypass via subject header spoofing
CVE-2026-15809 7.8 HIGH Github.com/cri-o/cri-o: fix bypass for cve-2022-4318 — /etc/passwd injection via home env
CVE-2026-14251 7.7 HIGH Gitops-operator: gitops-operator: missing allowednamespace check in reconcilerhook for clu

IV. Related Vulnerabilities

V. Comments for CVE-2026-15779

No comments yet


Leave a comment