CVE-2026-4408 @ Saiph
Package interrogation (copy)
Run on the host — click to copy a command. Debian/apt
| Package | Commands |
|---|---|
| samba-4.9.5+dfsg-5+deb10u5 | |
| samba-common-4.9.5+dfsg-5+deb10u5 | |
| samba-common-bin-4.9.5+dfsg-5+deb10u5 | |
| samba-dsdb-modules-4.9.5+dfsg-5+deb10u5 | |
| samba-libs-4.9.5+dfsg-5+deb10u5 | |
| samba-vfs-modules |
Inventory lookup
Search package inventory across systems, then return here. Create a ticket on systems the matcher missed.
Suggestions: samba · samba-common · samba-common-bin · samba-dsdb-modules · samba-libs · samba-vfs-modules
| System | Matches | Ticket for CVE-2026-4408 | |
|---|---|---|---|
| Archive | python-samba 2:4.9.5+dfsg-5+deb10u5; samba 2:4.9.5+dfsg-5+deb10u5; samba-common 2:4.9.5+dfsg-5+deb10u5; samba-common-bin 2:4.9.5+dfsg-5+deb10u5; samba-dsdb-modules 2:4.9.5+dfsg-5+deb10u5; samba-libs 2:4.9.5+dfsg-5+deb10u5; samba-vfs-modules 2:4.9.5+dfsg-5+deb10u5 | new open | |
| Library | python-samba 2:4.5.16+dfsg-1+deb9u4; samba 2:4.5.16+dfsg-1+deb9u4; samba-common 2:4.5.16+dfsg-1+deb9u4; samba-common-bin 2:4.5.16+dfsg-1+deb9u4; samba-dsdb-modules 2:4.5.16+dfsg-1+deb9u4; samba-libs 2:4.5.16+dfsg-1+deb9u4; samba-vfs-modules 2:4.5.16+dfsg-1+deb9u4 | new open | |
| Saiph | python-samba 2:4.9.5+dfsg-5+deb10u5; samba 2:4.9.5+dfsg-5+deb10u5; samba-common 2:4.9.5+dfsg-5+deb10u5; samba-common-bin 2:4.9.5+dfsg-5+deb10u5; samba-dsdb-modules 2:4.9.5+dfsg-5+deb10u5; samba-libs 2:4.9.5+dfsg-5+deb10u5; samba-vfs-modules 2:4.9.5+dfsg-5+deb10u5 | new open | |
| Bullseye | python3-samba 2:4.13.13+dfsg-1~deb11u8; samba 2:4.13.13+dfsg-1~deb11u8; samba-common 2:4.13.13+dfsg-1~deb11u8; samba-common-bin 2:4.13.13+dfsg-1~deb11u8; samba-dsdb-modules 2:4.13.13+dfsg-1~deb11u8; samba-libs 2:4.13.13+dfsg-1~deb11u8; samba-vfs-modules 2:4.13.13+dfsg-1~deb11u8 | none | |
| Matrix | python3-samba 2:4.17.12+dfsg-0+deb12u4; samba-common 2:4.17.12+dfsg-0+deb12u4; samba-common-bin 2:4.17.12+dfsg-0+deb12u4; samba-dsdb-modules 2:4.17.12+dfsg-0+deb12u4; samba-libs 2:4.17.12+dfsg-0+deb12u4 | none |
Same product CVEs in your queue
Other tickets that look like the same product (from match reason). Relate them here to triage this CVE as the primary.
| CVE | CVSS | KEV | Systems | Status | Matched | Already related | |
|---|---|---|---|---|---|---|---|
| CVE-2022-38023 | 8.1 | Archive, Bullseye, Library, Saiph | accepted_risk | samba-common-bin | — | ||
| CVE-2022-37966 | 8.1 | Archive, Bullseye, Library, Saiph | accepted_risk | samba-common-bin | — | ||
| CVE-2026-3644 | 7.5 | Library | accepted_risk | samba | — | ||
| CVE-2026-4224 | 7.5 | Library | accepted_risk | samba | — | ||
| CVE-2026-7210 | 7.5 | Library | accepted_risk | samba | → CVE-2026-15308 | ||
| CVE-2026-15308 | 7.5 | Library | accepted_risk | samba | — | ||
| CVE-2022-37967 | 7.2 | Archive, Bullseye, Library, Saiph | not_applicable | samba-common-bin | → CVE-2022-37966 |
Related CVE (same fix)
Point this ticket’s CVE at a higher-priority / same-fix primary so you only triage one.
Host OS / kernel
uname -r → 4.19.0-27-amd64uname -v → #1 SMP Debian 4.19.316-1 (2024-06-25)For Linux kernel CVEs, kernel_version (Debian packaging / build string) often decides fixed vs not; kernel_release is used for upstream NVD range compares.
Same CVE on other hosts
Open the ticket for this CVE on another system.
| System | Status | Priority | Updated | |
|---|---|---|---|---|
| Library | new | 5.2 | 2026-08-22T10:15:30Z | Open |
| Archive | new | 3.85 | 2026-08-22T10:15:30Z | Open |
Description
A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password script" feature. If this script is configured with the %u substitution character, the client-controlled username is passed without proper escaping of shell meta-characters. This vulnerability allows an attacker to achieve remote command execution on the affected system. This issue primarily affects non-standard configurations where the "check password script" is used with %u and the samba-dcerpcd service is started as a system service.
Update status
Add note only
References
- https://access.redhat.com/errata/RHSA-2026:22644
- https://access.redhat.com/errata/RHSA-2026:22963
- https://access.redhat.com/errata/RHSA-2026:25049
- https://access.redhat.com/errata/RHSA-2026:25979
- https://access.redhat.com/errata/RHSA-2026:28053
- https://access.redhat.com/errata/RHSA-2026:28054
- https://access.redhat.com/errata/RHSA-2026:28055
- https://access.redhat.com/errata/RHSA-2026:28056
- https://access.redhat.com/errata/RHSA-2026:28057
- https://access.redhat.com/errata/RHSA-2026:28058
- https://access.redhat.com/errata/RHSA-2026:28132
- https://access.redhat.com/errata/RHSA-2026:29799
- https://access.redhat.com/errata/RHSA-2026:29833
- https://access.redhat.com/errata/RHSA-2026:29863
- https://access.redhat.com/security/cve/CVE-2026-4408
NVD: CVE-2026-4408