Red Hat Product Errata RHSA-2026:28054 - Security Advisory Issued: 2026-06-23 Updated: 2026-06-23 RHSA-2026:28054 - Security Advisory Overview Updated Packages Synopsis Important: samba security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for samba is now available for Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description Samba is an open-source implementation of the Server Message Block (SMB) protocol and the related Common Internet File System (CIFS) protocol, which allow PC-compatible machines to share files, printers, and various information. Security Fix(es): samba: Missing access check on reparse point operations (CVE-2026-1933) samba: vfs_worm does not block directory modification (CVE-2026-2340) samba: group policy certificate enrollment uses http:// without validation (CVE-2026-3012) samba: Samba: Remote Code Execution in printing subsystem via unescaped job description (CVE-2026-4480) samba: Remote Code Execution in SAMR (CVE-2026-4408) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux Server - AUS 9.2 x86_64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.2 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.2 x86_64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.2 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.2 s390x Red Hat Enterprise Linux Resilient Storage for x86_64 - 4 years of updates 9.2 x86_64 Red Hat Enterprise Linux Resilient Storage for Power, little endian - 4 years of updates 9.2 ppc64le Red Hat Enterprise Linux Resilient Storage for IBM z Systems - 4 years of updates 9.2 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.2 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.2 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.2 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.2 s390x Red Hat Enterprise Linux Resilient Storage for Power, little endian - Extended Life Cycle 9.2 ppc64le Red Hat Enterprise Linux Resilient Storage for IBM z Systems - Extended Life Cycle 9.2 s390x Red Hat Enterprise Linux Resilient Storage for x86_64 - Extended Life Cycle 9.2 x86_64 Fixes BZ - 2447317 - CVE-2026-1933 samba: Missing access check on reparse point operations BZ - 2447318 - CVE-2026-2340 samba: vfs_worm does not block directory modification BZ - 2447319 - CVE-2026-3012 samba: group policy certificate enrollment uses http:// without validation BZ - 2452232 - CVE-2026-4480 samba: Samba: Remote Code Execution in printing subsystem via unescaped job description BZ - 2479762 - CVE-2026-4408 samba: Remote Code Execution in SAMR CVEs CVE-2026-1933 CVE-2026-2340 CVE-2026-3012 CVE-2026-4408 CVE-2026-4480 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux Server - AUS 9.2 SRPM samba-4.17.5-105.el9_2.5.src.rpm SHA-256: 72f20a2e6aedb69f7be34e35e617ae9e8dedb37caabcf406e9e8a0f60ee4b25d x86_64 ctdb-debuginfo-4.17.5-105.el9_2.5.i686.rpm SHA-256: 334c04b90ed46293b7bc39a5c3615135f629222a1ada81f2725cb5bf5a5c8055 ctdb-debuginfo-4.17.5-105.el9_2.5.x86_64.rpm SHA-256: 39373e9f5651a0b6f9755e55418121c066bdb8a673ffac416ef4403ea7349150 ctdb-debuginfo-4.17.5-105.el9_2.5.x86_64.rpm SHA-256: 39373e9f5651a0b6f9755e55418121c066bdb8a673ffac416ef4403ea7349150 libnetapi-4.17.5-105.el9_2.5.i686.rpm SHA-256: 393cb7f7a74d2d4682b0498b3d44bad37bd9a52589d313e295b9f72598b80382 libnetapi-4.17.5-105.el9_2.5.x86_64.rpm SHA-256: e5e722b07d07cf1d169876b235eea13f65bb90b3dd6a72c9a51dd89d71e8ab99 libnetapi-debuginfo-4.17.5-105.el9_2.5.i686.rpm SHA-256: 6313c271bdaf84280a9e930cc8f38c7db8745d5fc1b9b2fa1b6ca816d4317e0a libnetapi-debuginfo-4.17.5-105.el9_2.5.x86_64.rpm SHA-256: 37a7e76a805e2bf3872917e559c21a4b802a034c04119ada791104b1d8d1097f libnetapi-debuginfo-4.17.5-105.el9_2.5.x86_64.rpm SHA-256: 37a7e76a805e2bf3872917e559c21a4b802a034c04119ada791104b1d8d1097f libsmbclient-4.17.5-105.el9_2.5.i686.rpm SHA-256: 4fe00cff74c193e6761994d469871172aa1c15f77a9c2e9565bcbb8e55135525 libsmbclient-4.17.5-105.el9_2.5.x86_64.rpm SHA-256: 2d5d09b859fad46965378603d05eff5673ddc050e8e58c4a3b460afc1753536a libsmbclient-debuginfo-4.17.5-105.el9_2.5.i686.rpm SHA-256: c6487353c31b69db866951d8ea6e14cc0baa998e570f810530239fa7097a18ce libsmbclient-debuginfo-4.17.5-105.el9_2.5.x86_64.rpm SHA-256: 10a36c0893ee60c3edec524173df505899832690f1bdf7a85775e3ce0984e9c1 libsmbclient-debuginfo-4.17.5-105.el9_2.5.x86_64.rpm SHA-256: 10a36c0893ee60c3edec524173df505899832690f1bdf7a85775e3ce0984e9c1 libwbclient-4.17.5-105.el9_2.5.i686.rpm SHA-256: ed461a6fc91099fd9df05baaaa531df8c8ec38294bdabde48f3765e842ca0bc2 libwbclient-4.17.5-105.el9_2.5.x86_64.rpm SHA-256: 68f3d5e3bb5b41ff6cadbc0e6bbb02ce545ee36c304012c880476b75d10f38a8 libwbclient-debuginfo-4.17.5-105.el9_2.5.i686.rpm SHA-256: 2ee5474878fcc209b44a1d2a58e368e01ddfc48b49496af3e2a1336c153e0d6e libwbclient-debuginfo-4.17.5-105.el9_2.5.x86_64.rpm SHA-256: 5b3609ce99036ad36417cbd2efe495510b43bfd2a55aa31918ee720c34e65627 libwbclient-debuginfo-4.17.5-105.el9_2.5.x86_64.rpm SHA-256: 5b3609ce99036ad36417cbd2efe495510b43bfd2a55aa31918ee720c34e65627 python3-samba-4.17.5-105.el9_2.5.i686.rpm SHA-256: b0db9ec1c6ba4d819e4b5c72c2d34e14b097dfdb5a6429d92a0fa55b46475b9c python3-samba-4.17.5-105.el9_2.5.x86_64.rpm SHA-256: e5c0f300e622d416c4b50c07ab97b2e77c32d90ef4e89e207dc87ef18885dd7f python3-samba-dc-4.17.5-105.el9_2.5.x86_64.rpm SHA-256: 1a467deb0684ef5dfa912cccc3940204812d1821688c56790623ffdecae34072 python3-samba-dc-debuginfo-4.17.5-105.el9_2.5.i686.rpm SHA-256: 023f6d204ca90edf3bbf668a6f6e4aff9cc58918a8101766e98ad2283e226f39 python3-samba-dc-debuginfo-4.17.5-105.el9_2.5.x86_64.rpm SHA-256: 33939cce7795ef222d599ef646f4f9f065051bc9147380b9fdf85b8a3d213eee python3-samba-dc-debuginfo-4.17.5-105.el9_2.5.x86_64.rpm SHA-256: 33939cce7795ef222d599ef646f4f9f065051bc9147380b9fdf85b8a3d213eee python3-samba-debuginfo-4.17.5-105.el9_2.5.i686.rpm SHA-256: c614c1f7b2dbeaf126bd335aab5d4bc59c104376bb95761faa1d7576e1d63653 python3-samba-debuginfo-4.17.5-105.el9_2.5.x86_64.rpm SHA-256: 439b1e0257bd18a6897469b6ca09f89c963d1fdc3122c5151c6b869e89ae87b4 python3-samba-debuginfo-4.17.5-105.el9_2.5.x86_64.rpm SHA-256: 439b1e0257bd18a6897469b6ca09f89c963d1fdc3122c5151c6b869e89ae87b4 samba-4.17.5-105.el9_2.5.x86_64.rpm SHA-256: 8c77c3cfa01d169e65886e62f5d151a110b2f98958a8a15d6aa9cfe984db14db samba-client-4.17.5-105.el9_2.5.x86_64.rpm SHA-256: 7d9d7e4eae316efef64ce7fa68af23f319a9444d11fe988ceb042d1878d3378e samba-client-debuginfo-4.17.5-105.el9_2.5.i686.rpm SHA-256: b7a97120ad6397108d7294e9fe4b844909ecf935eaf508e968651ef754f1a3ad samba-client-debuginfo-4.17.5-105.el9_2.5.x86_64.rpm SHA-256: 25d335144a5558da8e626f2845fc6e11594fc8f58eb5353d8ae5481fa9724c38 samba-client-debuginfo-4.17.5-105.el9_2.5.x86_64.rpm SHA-256: 25d335144a5558da8e626f2845fc6e11594fc8f58eb5353d8ae5481fa9724c38 samba-client-libs-4.17.5-105.el9_2.5.i686.rpm SHA-256: dc6b37efd9382ca5fc1f3319eab7cff3c53d8df0f63da5dfced59ae3c0626390 samba-client-libs-4.17.5-105.el9_2.5.x86_64.rpm SHA-256: 900b5f1418102627aa7eb0689fb159314489604bc59e9384b9c16f415abcacf8 samba-client-libs-debuginfo-4.17.5-105.el9_2.5.i686.rpm SHA-256: 8195235afc58d6afb08af17f3e9e579e2ac3c5c8aefdd659667b1cb65ac0650d samba-client-libs-debuginfo-4.17.5-105.el9_2.5.x86_64.rpm SHA-256: bdf165cc25d573172ebf236a73aa8224af8d83438c1b0442d1dfa2a2434201e7 samba-client-libs-debuginfo-4.17.5-105.el9_2.5.x86_64.rpm SHA-256: bdf165cc25d573172ebf236a73aa8224af8d83438c1b0442d1dfa2a2434201e7 samba-common-4.17.5-105.el9_2.5.noarch.rpm SHA-256: a73441933e98234f227dc4fe7b01730e4c8d92d55c5065b507b4d8a7f51ebdbb samba-common-libs-4.17.5-105.el9_2.5.i686.rpm SHA-256: 74edea7eed5568c9047be6800936f4e85e52ff509181fd4832ec5808312dfe04 samba-common-libs-4.17.5-105.el9_2.5.x86_64.rpm SHA-256: 6fc437c9de10a1f42380ac06d8245cd2ef054936445e2df7e0289dc59f060e61 samba-common-libs-debuginfo-4.17.5-105.el9_2.5.i686.rpm SHA-256: 946406f61d44ce406963ba9d106581c50254dc2b22c2c730a744f226d14ad486 samba-common-libs-debuginfo-4.17.5-105.el9_2.5.x86_64.rpm SHA-256: a7d2109cdeb8bf249977c50d12208bd60910c1cdf2bb27fe1ff4b4965a5ea9e4 samba-common-libs-debuginfo-4.17.5-105.el9_2.5.x86_64.rpm SHA-256: a7d2109cdeb8bf249977c50d12208bd60910c1cdf2bb27fe1ff4b4965a5ea9e4 samba-common-tools-4.17.5-105.el9_2.5.x86_64.rpm SHA-256: f656e1650706089cde2ce87fa6ff17b84644a67b0242a49ce1df8c0e963bb421 samba-common-tools-debuginfo-4.17.5-105.el9_2.5.i686.rpm SHA-256: c9510266bc34a37c4b6c9b9130a7e23f876989851a650139a7fff3260293edbc samba-common-tools-debuginfo-4.17.5-105.el9_2.5.x86_64.rpm SHA-256: 416b756440f1e566231cd202f4d15342e1a4ef2d4bde4fbb8282fd16cf29619d samba-common-tools-debuginfo-4.17.5-105.el9_2.5.x86_64.rpm SHA-256: 416b756440f1e566231cd202f4d15342e1a4ef2d4bde4fbb8282fd16cf29619d samba-dc-libs-4.17.5-105.el9_2.5.i686.rpm SHA-256: b66db1c02befcdf2f3e00e8abd9dda7f3b062fc9c939f75dd33d89d88098b915 samba-dc-libs-4.17.5-105.el9_2.5.x86_64.rpm SHA-256: 317646f903dfd636270597f5c4081ddc9404b87b8cf62feef93f101465d6ec2a samba-dc-libs-debuginfo-4.17.5-105.el9_2.5.i686.rpm SHA-256: 6da1d2329cd88bb7d6b39154f25c529bfbfe
This Red Hat security advisory addresses multiple vulnerabilities in Samba, including two critical remote code execution flaws in the printing subsystem (CVE-2026-4480) and SAMR (CVE-2026-4408), along with other security issues. The CVSS base score for CVE-2026-1933 is 7.1 (High). According to NVD data, affected versions include Samba 4.1.0 through 4.2.1, which is fixed in version 4.2.2.