Fedora Account System
Red Hat Associate
Red Hat Customer
Samba: Missing access check on reparse point operations
Embargo Lifted. The CVE is now public. https://www.samba.org/samba/security/CVE-2026-1933.html https://bugzilla.samba.org/show_bug.cgi?id=15992
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:22963 https://access.redhat.com/errata/RHSA-2026:22963
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:25049 https://access.redhat.com/errata/RHSA-2026:25049
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:25979 https://access.redhat.com/errata/RHSA-2026:25979
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On Via RHSA-2026:28057 https://access.redhat.com/errata/RHSA-2026:28057
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2026:28056 https://access.redhat.com/errata/RHSA-2026:28056
This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:28055 https://access.redhat.com/errata/RHSA-2026:28055
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2026:28054 https://access.redhat.com/errata/RHSA-2026:28054
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions Via RHSA-2026:28053 https://access.redhat.com/errata/RHSA-2026:28053
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.19 Via RHSA-2026:29863 https://access.redhat.com/errata/RHSA-2026:29863
PSIRTSUPT-20948: TAM flagged that OCP 4.20 was missing from the CVE page. Investigation confirmed that active streams openshift-4.20, openshift-4.21, and openshift-4.22 had no affects filed, despite shipping the same vulnerable samba RPMs via RHCOS (RHEL 9.6 base). Added AFFECTED/DELEGATED affects for all three streams to match the existing pattern (openshift-4.12.z through openshift-4.19).