Fedora Account System
Red Hat Associate
Red Hat Customer
Samba file servers and classic (non-AD) domain controllers offer the SamValidatePasswordChange and SamValidatePasswordReset RPC services on the SAMR DCE/RPC service when running over NCACN_IP_TCP. Both services pass a username and password to the "check password script" that can be configured in smb.conf. If the "check password script" is configured with the %u substitution character, the client-controlled username is passed to the "check password script" without escaping shell meta-characters, leading to a remote command execution vulnerability. This is a non-standard configuration in several ways: It affects Samba file servers and classic (non-AD) domain controllers that have the "check password script" configured with the %u substitution character. Active Directory Domain Controllers are not affected, they do not expand the username via the %u substitution character. The problem is much less dangerous if %u has single quotes directly around it, e.g. '%u', but it's still possible to inject command line options. Standard Samba file servers and classic domain controllers are also only affected if the samba-dcerpcd service is started as a system service, which can only happen if "rpc start on demand helpers" is set to the non-default setting "no". In the default configuration for DCE/RPC, smbd starts the samba-dcerpcd in a way that makes the vulnerable code inaccessible.
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:22644 https://access.redhat.com/errata/RHSA-2026:22644
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:22963 https://access.redhat.com/errata/RHSA-2026:22963
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:25049 https://access.redhat.com/errata/RHSA-2026:25049
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:25979 https://access.redhat.com/errata/RHSA-2026:25979
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On Via RHSA-2026:28058 https://access.redhat.com/errata/RHSA-2026:28058
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On Via RHSA-2026:28057 https://access.redhat.com/errata/RHSA-2026:28057
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2026:28056 https://access.redhat.com/errata/RHSA-2026:28056
This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:28055 https://access.redhat.com/errata/RHSA-2026:28055
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2026:28054 https://access.redhat.com/errata/RHSA-2026:28054
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions Via RHSA-2026:28053 https://access.redhat.com/errata/RHSA-2026:28053
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Extended Lifecycle Support Via RHSA-2026:28132 https://access.redhat.com/errata/RHSA-2026:28132
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.21 Via RHSA-2026:29833 https://access.redhat.com/errata/RHSA-2026:29833
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.20 Via RHSA-2026:29799 https://access.redhat.com/errata/RHSA-2026:29799
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.19 Via RHSA-2026:29863 https://access.redhat.com/errata/RHSA-2026:29863