Description
A flaw was found in Samba's internal DNS server where unauthenticated TKEY registration requests were added to the TKEY name cache before being rejected. A remote, unauthenticated attacker can exploit this behavior by sending a large number of TKEY requests with arbitrary names, exhausting the cache and evicting legitimate TKEY entries. This can prevent legitimate TSIG authentication for signed DNS queries, resulting in a denial of service.
Published: 2026-07-30
Score: 5.3 Medium
EPSS: 1.1% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Samba’s internal DNS server allows unauthenticated TKEY registration requests to be cached before rejection; a remote attacker can flood the server with many such requests using arbitrary names, causing cache exhaustion that evicts legitimate TKEY entries. The result is that legitimate TSIG authentication for signed DNS queries fails, leading to a denial of service for DNS signing and related services.

Affected Systems

The vulnerability affects Samba running on Red Enterprise Linux 6 through 10 and on Red OpenShift Container Platform 4. No specific Samba version is listed; any installation of Samba on these platforms that supports DNS signing is potentially vulnerable.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity, and the EPSS score of 1% suggests a low but non‑zero exploitation potential. The lack of a KEV listing combined with the remote unauthenticated nature of the attack indicates that the vulnerability is realistic but unlikely to be widely exploited. An attacker would need only network access to the machine’s DNS service to trigger the denial of service by sending a high volume of TKEY requests.

Generated by OpenCVE AI on August 2, 2026 at 05:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Samba to a version that has corrected the cache handling flaw, following the Red Hat security advisory for CVE‑2026‑58218
  • Configure the TKEY name cache to impose a stricter size limit or disable TKEY usage if it is not required, to prevent excessive memory consumption
  • Implement network‑layer controls such as DNS firewall rules or rate‑limiting to reduce the impact of large volumes of TKEY requests from untrusted hosts

Generated by OpenCVE AI on August 2, 2026 at 05:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6401-1 samba security update
Ubuntu USN Ubuntu USN USN-8621-1 Samba vulnerabilities
History

Fri, 31 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Thu, 30 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Redhat openshift Container Platform
Samba
Samba samba
Vendors & Products Redhat openshift Container Platform
Samba
Samba samba

Thu, 30 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 14:15:00 +0000

Type Values Removed Values Added
Description A flaw was found in Samba's internal DNS server where unauthenticated TKEY registration requests were added to the TKEY name cache before being rejected. A remote, unauthenticated attacker can exploit this behavior by sending a large number of TKEY requests with arbitrary names, exhausting the cache and evicting legitimate TKEY entries. This can prevent legitimate TSIG authentication for signed DNS queries, resulting in a denial of service.
Title Samba: dns signing dos via tkey name cache exhaustion
First Time appeared Redhat
Redhat enterprise Linux
Redhat openshift
Weaknesses CWE-410
CPEs cpe:/a:redhat:openshift:4
cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
Redhat openshift
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Redhat Enterprise Linux Openshift Openshift Container Platform
Samba Samba
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-07-30T17:37:18.466Z

Reserved: 2026-06-29T18:13:08.160Z

Link: CVE-2026-58218

cve-icon Vulnrichment

Updated: 2026-07-30T17:35:02.687Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-07-30T14:17:00.307

Modified: 2026-07-30T19:18:26.480

Link: CVE-2026-58218

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-07-28T10:00:00Z

Links: CVE-2026-58218 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T05:30:06Z

Weaknesses
  • CWE-410

    Insufficient Resource Pool