CVE-2026-58218 on CTRL-OS 26.05
Aliases: CVE-2026-58218
Packages: samba
Status: Plausible
Advisory Information
A flaw was found in Samba's internal DNS server where unauthenticated TKEY registration requests were added to the TKEY name cache before being rejected. A remote, unauthenticated attacker can exploit this behavior by sending a large number of TKEY requests with arbitrary names, exhausting the cache and evicting legitimate TKEY entries. This can prevent legitimate TSIG authentication for signed DNS queries, resulting in a denial of service.
Updates
2026-07-28 22:35 CEST
Metadata changes:
- Status for package
samba: “Plausible”
2026-07-28 22:27 CEST
Metadata changes:
- Status for package
samba: “New”