Samba是Samba开源的一个适用于 Linux 和 Unix 的标准 Windows 互操作性程序套件。 Samba存在访问控制错误漏洞,该漏洞源于处理NTFS风格重解析点时缺少SMB层访问检查,可能导致经过身份验证的用户在只读导出上创建或删除重解析点元数据,包括将文件转换为符号链接或其他重解析点类型。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | 0:4.23.5-109.el10_2 ~ * |
cpe:/o:redhat:enterprise_linux:10.2
|
|
| Red Hat | Red Hat Enterprise Linux 10.0 Extended Update Support | 0:4.21.3-114.el10_0.1 ~ * |
cpe:/o:redhat:enterprise_linux_eus:10.0
|
|
| Red Hat | Red Hat Enterprise Linux 8 | 0:4.19.4-16.el8_10 ~ * |
cpe:/a:redhat:enterprise_linux:8::appstream
|
|
| Red Hat | Red Hat Enterprise Linux 8 | 0:4.19.4-16.el8_10 ~ * |
cpe:/a:redhat:enterprise_linux:8::appstream
|
|
| Red Hat | Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | 0:4.15.5-16.el8_6.1 ~ * |
cpe:/a:redhat:rhel_aus:8.6::appstream
|
|
| Red Hat | Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On | 0:4.15.5-16.el8_6.1 ~ * |
cpe:/a:redhat:rhel_aus:8.6::appstream
|
|
| Red Hat | Red Hat Enterprise Linux 8.8 Telecommunications Update Service | 0:4.17.5-7.el8_8.1 ~ * |
cpe:/a:redhat:rhel_e4s:8.8::appstream
|
|
| Red Hat | Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | 0:4.17.5-7.el8_8.1 ~ * |
cpe:/a:redhat:rhel_e4s:8.8::appstream
|
|
| Red Hat | Red Hat Enterprise Linux 9 | 0:4.23.5-10.el9_8 ~ * |
cpe:/a:redhat:enterprise_linux:9::appstream
|
|
| Red Hat | Red Hat Enterprise Linux 9 | 0:4.23.5-10.el9_8 ~ * |
cpe:/a:redhat:enterprise_linux:9::appstream
|
|
| Red Hat | Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | 0:4.17.5-105.el9_2.5 ~ * |
cpe:/a:redhat:rhel_e4s:9.2::appstream
|
|
| Red Hat | Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions | 0:4.19.4-105.el9_4.4 ~ * |
cpe:/a:redhat:rhel_e4s:9.4::appstream
|
|
| Red Hat | Red Hat Enterprise Linux 9.6 Extended Update Support | 0:4.21.3-14.el9_6.1 ~ * |
cpe:/a:redhat:rhel_eus:9.6::appstream
|
|
| Red Hat | Red Hat OpenShift Container Platform 4.12 | 412.86.202608241157-0 ~ * |
cpe:/a:redhat:openshift:4.12::el8
|
|
| Red Hat | Red Hat OpenShift Container Platform 4.13 | 413.92.202609080414-0 ~ * |
cpe:/a:redhat:openshift:4.13::el9
|
|
| Red Hat | Red Hat OpenShift Container Platform 4.14 | 414.92.202608172040-0 ~ * |
cpe:/a:redhat:openshift:4.14::el9
|
|
| Red Hat | Red Hat OpenShift Container Platform 4.15 | 415.92.202608180329-0 ~ * |
cpe:/a:redhat:openshift:4.15::el9
|
|
| Red Hat | Red Hat OpenShift Container Platform 4.16 | 416.94.202608150307-0 ~ * |
cpe:/a:redhat:openshift:4.16::el9
|
|
| Red Hat | Red Hat OpenShift Container Platform 4.17 | 417.94.202608250221-0 ~ * |
cpe:/a:redhat:openshift:4.17::el9
|
|
| Red Hat | Red Hat OpenShift Container Platform 4.18 | 418.94.202608142238-0 ~ * |
cpe:/a:redhat:openshift:4.18::el9
|
|
| Red Hat | Red Hat OpenShift Container Platform 4.19 | 4.19.9.6.202606241344-0 ~ * |
cpe:/a:redhat:openshift:4.19::el9
|
|
| Red Hat | Red Hat OpenShift Container Platform 4.20 | 4.20.9.6.202608121719-0 ~ * |
cpe:/a:redhat:openshift:4.20::el9
|
|
| Red Hat | Red Hat OpenShift Container Platform 4.21 | 4.21.9.6.202608122143-0 ~ * |
cpe:/a:redhat:openshift:4.21::el9
|
|
| Red Hat | Red Hat OpenShift Container Platform 4.22 | 4.22.9.8.202608130832-0 ~ * |
cpe:/a:redhat:openshift:4.22::el9
|
|
| Red Hat | Red Hat Enterprise Linux 6 | - |
cpe:/o:redhat:enterprise_linux:6
|
|
| Red Hat | Red Hat Enterprise Linux 6 | - |
cpe:/o:redhat:enterprise_linux:6
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat OpenShift Container Platform 4 | - |
cpe:/a:redhat:openshift:4
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-3012 | 8.0 HIGH | Samba: group policy certificate enrollment uses http:// without validation |
| CVE-2026-9704 | 6.8 MEDIUM | Keycloak: keycloak: privilege escalation due to oversized subject_token jwt |
| CVE-2026-2340 | 6.5 MEDIUM | Samba: vfs_worm does not block directory modification |
| CVE-2026-9689 | 4.2 MEDIUM | Keycloak: org.keycloak.protocol.oidc: http parameter pollution in oidc redirect uri allows |
No comments yet