Bug 2447319 (CVE-2026-3012)
| Summary: | CVE-2026-3012 samba: group policy certificate enrollment uses http:// without validation | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security <prodsec-ir-bot> |
| Status: | NEW --- | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | CC: | rhel-process-autobot, security-response-team, villapla, watson-tool-maintainers |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in Samba’s certificate auto-enrollment Group Policy handling. When certificate auto-enrollment is enabled, Samba may retrieve a CA certificate over an unencrypted HTTP connection and install it into the local trust store without proper verification. An attacker with the ability to intercept or redirect network traffic could exploit this behavior to supply a malicious certificate authority certificate, potentially allowing interception or spoofing of trusted communications.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2481857 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2026-03-13 13:05:22 UTC
Embargo Lifted. The CVE is public now: https://bugzilla.samba.org/show_bug.cgi?id=16003 https://attachments.samba.org/attachment.cgi?id=18990 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:22644 https://access.redhat.com/errata/RHSA-2026:22644 This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:22963 https://access.redhat.com/errata/RHSA-2026:22963 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:25049 https://access.redhat.com/errata/RHSA-2026:25049 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:25979 https://access.redhat.com/errata/RHSA-2026:25979 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On Via RHSA-2026:28057 https://access.redhat.com/errata/RHSA-2026:28057 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2026:28056 https://access.redhat.com/errata/RHSA-2026:28056 This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:28055 https://access.redhat.com/errata/RHSA-2026:28055 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2026:28054 https://access.redhat.com/errata/RHSA-2026:28054 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions Via RHSA-2026:28053 https://access.redhat.com/errata/RHSA-2026:28053 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.19 Via RHSA-2026:29863 https://access.redhat.com/errata/RHSA-2026:29863 |