Red Hat Product Errata RHSA-2026:28053 - Security Advisory Issued: 2026-06-23 Updated: 2026-06-23 RHSA-2026:28053 - Security Advisory Overview Updated Packages Synopsis Important: samba security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for samba is now available for Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description Samba is an open-source implementation of the Server Message Block (SMB) protocol and the related Common Internet File System (CIFS) protocol, which allow PC-compatible machines to share files, printers, and various information. Security Fix(es): samba: Missing access check on reparse point operations (CVE-2026-1933) samba: vfs_worm does not block directory modification (CVE-2026-2340) samba: group policy certificate enrollment uses http:// without validation (CVE-2026-3012) samba: Samba: Remote Code Execution in printing subsystem via unescaped job description (CVE-2026-4480) samba: Remote Code Execution in SAMR (CVE-2026-4408) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux Server - AUS 9.4 x86_64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.4 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.4 x86_64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.4 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.4 s390x Red Hat Enterprise Linux Resilient Storage for x86_64 - 4 years of updates 9.4 x86_64 Red Hat Enterprise Linux Resilient Storage for Power, little endian - 4 years of updates 9.4 ppc64le Red Hat Enterprise Linux Resilient Storage for IBM z Systems - 4 years of updates 9.4 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.4 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.4 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.4 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.4 s390x Red Hat Enterprise Linux Resilient Storage for Power, little endian - Extended Life Cycle 9.4 ppc64le Red Hat Enterprise Linux Resilient Storage for IBM z Systems - Extended Life Cycle 9.4 s390x Red Hat Enterprise Linux Resilient Storage for x86_64 - Extended Life Cycle 9.4 x86_64 Fixes BZ - 2447317 - CVE-2026-1933 samba: Missing access check on reparse point operations BZ - 2447318 - CVE-2026-2340 samba: vfs_worm does not block directory modification BZ - 2447319 - CVE-2026-3012 samba: group policy certificate enrollment uses http:// without validation BZ - 2452232 - CVE-2026-4480 samba: Samba: Remote Code Execution in printing subsystem via unescaped job description BZ - 2479762 - CVE-2026-4408 samba: Remote Code Execution in SAMR CVEs CVE-2026-1933 CVE-2026-2340 CVE-2026-3012 CVE-2026-4408 CVE-2026-4480 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux Server - AUS 9.4 SRPM samba-4.19.4-105.el9_4.4.src.rpm SHA-256: cef588647d23a14046b9d15c35571cb4332679d9d081ee2c7572ad307a6f298b x86_64 ctdb-debuginfo-4.19.4-105.el9_4.4.i686.rpm SHA-256: ab076a838b7c780fea4b031e877fc2c8f4614f194caf97bad2b31e677bbd8fb0 ctdb-debuginfo-4.19.4-105.el9_4.4.x86_64.rpm SHA-256: 9e2f9c66408baca8c7ec1eec981a1eccae2bb83fc644a1094bd5585957e8d5f0 ctdb-debuginfo-4.19.4-105.el9_4.4.x86_64.rpm SHA-256: 9e2f9c66408baca8c7ec1eec981a1eccae2bb83fc644a1094bd5585957e8d5f0 libnetapi-4.19.4-105.el9_4.4.i686.rpm SHA-256: 90399e429a24582be20e73b2da10c36616d5cacfd106df5f3f97bbd0dfb15bdc libnetapi-4.19.4-105.el9_4.4.x86_64.rpm SHA-256: f5bb0983666ae9fcbe612903cd427ca86b44f073fa5081899d24ca501478d176 libnetapi-debuginfo-4.19.4-105.el9_4.4.i686.rpm SHA-256: cedfc698f8989031c5af9cfc02e321c8ef30a965ecf55252013dc837074c483e libnetapi-debuginfo-4.19.4-105.el9_4.4.x86_64.rpm SHA-256: cb372670f43d43789d25204b8f5871e747f2ed2e19fea500d910e81980151aff libnetapi-debuginfo-4.19.4-105.el9_4.4.x86_64.rpm SHA-256: cb372670f43d43789d25204b8f5871e747f2ed2e19fea500d910e81980151aff libsmbclient-4.19.4-105.el9_4.4.i686.rpm SHA-256: 9edc1b0bf78bb3e84b93328f2bf00f1315c7c4efef70cc854d5673efdea1f7da libsmbclient-4.19.4-105.el9_4.4.x86_64.rpm SHA-256: 1a864135d0a1bc46c2cc12a5b395d8293748e601c7cfbead2353757959fdcfb3 libsmbclient-debuginfo-4.19.4-105.el9_4.4.i686.rpm SHA-256: e09fbc99f745d917525c8a510e8b395da81c5121226f55984b27df1f8d22e25e libsmbclient-debuginfo-4.19.4-105.el9_4.4.x86_64.rpm SHA-256: aa0b50fd423cc1a8dbb81c0f60ca71bcf439b6e6d89df450db1b836055e721f6 libsmbclient-debuginfo-4.19.4-105.el9_4.4.x86_64.rpm SHA-256: aa0b50fd423cc1a8dbb81c0f60ca71bcf439b6e6d89df450db1b836055e721f6 libwbclient-4.19.4-105.el9_4.4.i686.rpm SHA-256: 25ffedae68747d47f0eef4953e81abf3fc1e2a3996708ee7a8e0871683296097 libwbclient-4.19.4-105.el9_4.4.x86_64.rpm SHA-256: 9cdc8b40a55286e6fc4106d907f13d75e138f9ac9d271d10279a0133cabc113e libwbclient-debuginfo-4.19.4-105.el9_4.4.i686.rpm SHA-256: f31bbda13028c0201651cbdde1c51ef65bd599fadbe79dc362ab06b6c6a52bfb libwbclient-debuginfo-4.19.4-105.el9_4.4.x86_64.rpm SHA-256: 1ed83bf94a7c4b388dc3bc96db3a193a3fc918a97ea2fef818ac353375eb06a1 libwbclient-debuginfo-4.19.4-105.el9_4.4.x86_64.rpm SHA-256: 1ed83bf94a7c4b388dc3bc96db3a193a3fc918a97ea2fef818ac353375eb06a1 python3-samba-4.19.4-105.el9_4.4.i686.rpm SHA-256: ab52dbc69a046623ef80244f0be6356d12c0b61e200b9861bc58cf0cf8b20a66 python3-samba-4.19.4-105.el9_4.4.x86_64.rpm SHA-256: cdc41ca843a96e777e7250f58ad60dd41d772c95bd4b18912e6fe06836af47ab python3-samba-dc-4.19.4-105.el9_4.4.x86_64.rpm SHA-256: 0afd88216cf1f5c6b2a7917ed0c290c42e2b3bf4462b5f16ef9612db35510dd8 python3-samba-dc-debuginfo-4.19.4-105.el9_4.4.i686.rpm SHA-256: e9c57af5417019dcee0435a8c3d2583b6fb8ea1176c96b1f0fbac335f82d0c7e python3-samba-dc-debuginfo-4.19.4-105.el9_4.4.x86_64.rpm SHA-256: 8397635dc3b3f5c12d294577f2c8dd2e3af125c6e1224f37bec4fc916a221a1c python3-samba-dc-debuginfo-4.19.4-105.el9_4.4.x86_64.rpm SHA-256: 8397635dc3b3f5c12d294577f2c8dd2e3af125c6e1224f37bec4fc916a221a1c python3-samba-debuginfo-4.19.4-105.el9_4.4.i686.rpm SHA-256: 21ad7dc3e60b9c191f354452f96dfda35db4d43c3ea48575d53cd762a9508f9d python3-samba-debuginfo-4.19.4-105.el9_4.4.x86_64.rpm SHA-256: 350cfafe86a4b97812d5efa098712ac3bb4c76b4bb0c6170f8c52b5e4e0e9dfc python3-samba-debuginfo-4.19.4-105.el9_4.4.x86_64.rpm SHA-256: 350cfafe86a4b97812d5efa098712ac3bb4c76b4bb0c6170f8c52b5e4e0e9dfc samba-4.19.4-105.el9_4.4.x86_64.rpm SHA-256: 5549fdcc2778969cbcd7c0a65fa75d5b3d4a34a87bf7a9930177f3721cc571f0 samba-client-4.19.4-105.el9_4.4.x86_64.rpm SHA-256: 1d74ddf3b2c080f061e3f32785c43e9ce03a70e1abbe07a557ab21b8dad30858 samba-client-debuginfo-4.19.4-105.el9_4.4.i686.rpm SHA-256: d500afe7737552082b5a1f70d4b4c61f2de7c29e9099e23cf13638df8e5da1ab samba-client-debuginfo-4.19.4-105.el9_4.4.x86_64.rpm SHA-256: c334454ec8d9fb1d77bf58c76b4f57585d448c4aaec7d0c269e6cadee8e5ec95 samba-client-debuginfo-4.19.4-105.el9_4.4.x86_64.rpm SHA-256: c334454ec8d9fb1d77bf58c76b4f57585d448c4aaec7d0c269e6cadee8e5ec95 samba-client-libs-4.19.4-105.el9_4.4.i686.rpm SHA-256: 22bc32e0f5d6110bd81ded4df52655007f2b2f7b4dec18667c4512555e0c3158 samba-client-libs-4.19.4-105.el9_4.4.x86_64.rpm SHA-256: 3d593ed1be04a507f8eea4bffc5b826b18f812e046d2b014117c516387983bec samba-client-libs-debuginfo-4.19.4-105.el9_4.4.i686.rpm SHA-256: e24975abc65adffef180e1507bfffada538ebf7a87e5fafaf6326bfd58bc7336 samba-client-libs-debuginfo-4.19.4-105.el9_4.4.x86_64.rpm SHA-256: 134941540fc68f1086cc2734d291186cd5c39cd98cd312209f3bc82aec1fb61e samba-client-libs-debuginfo-4.19.4-105.el9_4.4.x86_64.rpm SHA-256: 134941540fc68f1086cc2734d291186cd5c39cd98cd312209f3bc82aec1fb61e samba-common-4.19.4-105.el9_4.4.noarch.rpm SHA-256: d9dd1369f3ab22744b1459639d1e6070e9296da110637e2dc7b1d68ab38646d1 samba-common-libs-4.19.4-105.el9_4.4.i686.rpm SHA-256: 590da98a0e5e8c2ad6c342da4900147845c2949e8cee1d9655f61fa451db661e samba-common-libs-4.19.4-105.el9_4.4.x86_64.rpm SHA-256: f6beafa436e32617f837397b41e8f6eb080b98291afe04c11e44c9a39d803133 samba-common-libs-debuginfo-4.19.4-105.el9_4.4.i686.rpm SHA-256: 654ceb1d769d1a21f7f2e72633f262f6085c32691d96b350c598ca2bb15581bf samba-common-libs-debuginfo-4.19.4-105.el9_4.4.x86_64.rpm SHA-256: b3bb91b837671e917c73b5eea2d8c0c1f581236e26fec2796bc55412aeacbac6 samba-common-libs-debuginfo-4.19.4-105.el9_4.4.x86_64.rpm SHA-256: b3bb91b837671e917c73b5eea2d8c0c1f581236e26fec2796bc55412aeacbac6 samba-common-tools-4.19.4-105.el9_4.4.x86_64.rpm SHA-256: 57023717b2aed06aea555e45c0a4a270fd54227ce1aff7c4b2941b009b84ffc5 samba-common-tools-debuginfo-4.19.4-105.el9_4.4.i686.rpm SHA-256: 88c51066f5742929f4ccbbc8dc581cb9c60d8f935fc81816b12399baa673f06b samba-common-tools-debuginfo-4.19.4-105.el9_4.4.x86_64.rpm SHA-256: 40a1df6ea9051b22b22f8d11d2aee517a1be2c5f1769618575e99fb51955b603 samba-common-tools-debuginfo-4.19.4-105.el9_4.4.x86_64.rpm SHA-256: 40a1df6ea9051b22b22f8d11d2aee517a1be2c5f1769618575e99fb51955b603 samba-dc-libs-4.19.4-105.el9_4.4.i686.rpm SHA-256: 73475872e684563892d08f6b82f33c651b35cc45f40349fd63a510ae8424ef19 samba-dc-libs-4.19.4-105.el9_4.4.x86_64.rpm SHA-256: 1945adb8481b218c87fe67511cd3b46ac3ae1fef3c62727a51b54c8da310f998 samba-dc-libs-debuginfo-4.19.4-105.el9_4.4.i686.rpm SHA-256: 4462bee562832d06e4f5c8d746d3c9fa0a71
This Red Hat security advisory addresses multiple vulnerabilities in Samba for RHEL 9.4, including two critical remote code execution flaws (CVE-2026-4480 via the printing subsystem and CVE-2026-4408 via SAMR), a missing access check on reparse points (CVE-2026-1933), insecure HTTP use in group policy certificate enrollment (CVE-2026-3012), and a vfs_worm bypass (CVE-2026-2340). Red Hat Product Security has rated this update as having a security impact of Important, with individual CVSS scores available via the linked CVE pages. The advisory provides updated packages for multiple RHEL 9.4 architectures and Update Services; specific patched version numbers are not provided in the excerpt, but the solution references Red Hat's standard update application procedures.