← Voltar à pesquisa de CVEs

CVE-2026-3238

Samba

Descrição

A flaw was found in Samba-s WINS server component when running as an Active Directory Domain Controller. The WINS protocol handlers for certain request types did not properly validate incoming packets, allowing an unauthenticated remote attacker to trigger a NULL pointer dereference and crash the WINS service using specially crafted UDP packets.

CVSS 7.5EPSS 2.669%Risco 0.93
Ver fonte
Publicação
2026-06-08 09:16:30
Versões afetadas
unknown
Tipo
Core software
Última alteração
2026-07-23 07:10:00
Vetor
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H