Bug 2502730 (CVE-2026-6949)
| Summary: | CVE-2026-6949 samba: TSIG packet with crafted name compression can crash DNS server | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security <prodsec-ir-bot> |
| Status: | NEW --- | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | CC: | rhel-process-autobot, security-response-team, watson-tool-maintainers |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in Samba's internal DNS server when processing TSIG-signed DNS packets containing compressed names. Incorrect size calculations while determining the portion of the DNS packet covered by the TSIG signature can result in an integer underflow, leading to an out-of-bounds memory write during packet processing. A remote attacker can send a specially crafted TSIG-signed DNS packet to cause the DNS server to terminate unexpectedly.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2509257 | ||
| Bug Blocks: | |||
| Deadline: | 2026-07-28 | ||
|
Description
OSIDB Bzimport
2026-07-20 11:06:39 UTC
|