SUSE-CU-2026:8018-1: Security update of suse/samba-server

sle-container-updates at lists.suse.com sle-container-updates at lists.suse.com
Wed Aug 5 10:22:20 UTC 2026


SUSE Container Update Advisory: suse/samba-server
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:8018-1
Container Tags        : suse/samba-server:4.21 , suse/samba-server:4.21 , suse/samba-server:4.21-76.2 , suse/samba-server:latest
Container Release     : 76.2
Severity              : important
Type                  : security
References            : 1271469 1271672 1271673 1271674 1271675 1271676 1271677 CVE-2026-15779
                        CVE-2026-58216 CVE-2026-58218 CVE-2026-58221 CVE-2026-58222 CVE-2026-58224
                        CVE-2026-6949 
-----------------------------------------------------------------

The container suse/samba-server was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3363-1
Released:    Tue Jul 28 14:19:01 2026
Summary:     Security update for samba
Type:        security
Severity:    important
References:  1271469,1271672,1271673,1271674,1271675,1271676,1271677,CVE-2026-15779,CVE-2026-58216,CVE-2026-58218,CVE-2026-58221,CVE-2026-58222,CVE-2026-58224,CVE-2026-6949
This update for samba fixes the following issues

- CVE-2026-6949: TSIG packet with crafted name compression can crash internal DNS server (bsc#1271672).
- CVE-2026-15779: `pam_winbind` module with `mkhomedir` set allows `chown` of critical system paths without validation
  (bsc#1271469).
- CVE-2026-58216: 6-byte heap OOB read in packet parser of the `kpasswd` service (bsc#1271674).
- CVE-2026-58218: DNS TKEY negotiation stores unauthenticated GSS contexts in a fixed FIFO before authentication
  completes (bsc#1271675).
- CVE-2026-58221: authenticated LDAP access to internal LDB special DNs permits domain takeover (bsc#1271676).
- CVE-2026-58222: LDAP Compare filter injection and trusted-request confusion disclose protected attributes
  (bsc#1271677).
- CVE-2026-58224: heap OOB read due to unchecked packet length fields in CTDB (bsc#1271673).


The following package changes have been done:

- libldb2-4.21.10+git.533.31d7e5508d-150700.3.29.1 updated
- samba-client-libs-4.21.10+git.533.31d7e5508d-150700.3.29.1 updated
- samba-libs-4.21.10+git.533.31d7e5508d-150700.3.29.1 updated
- samba-client-4.21.10+git.533.31d7e5508d-150700.3.29.1 updated
- samba-dcerpc-4.21.10+git.533.31d7e5508d-150700.3.29.1 updated
- samba-4.21.10+git.533.31d7e5508d-150700.3.29.1 updated
- container:suse-sle15-15.7-0411096f465658d23cf7197d39261fa8d818d8fc75c5ad5ce0e68f97a657663f-0 updated


More information about the sle-container-updates mailing list