A flaw was found in samba's pam_winbind.
A flaw was found in samba's pam_winbind. When mkhomedir is enabled, pam_winbind chowns the target account's home directory without validating the path is not a critical system directory such as /. On affected systems, accounts with / as their home directory (a common default for system accounts) can have this triggered not only by root, but by a non-root user holding a narrow sudo delegation to run commands as that account, causing ownership of / to change and resulting in severe denial of service (SSH, sudo, and package-manager failures). The change does not grant write access to / (which ships with restrictive 0555 permissions on RHEL), so the impact is availability loss rather than further privilege escalation.
A flaw was found in samba's pam_winbind.
Description
A flaw was found in samba's pam_winbind. When mkhomedir is enabled, pam_winbind chowns the target account's home directory without validating the path is not a critical system directory such as /. On affected systems, accounts with / as their home directory (a common default for system accounts) can have this triggered not only by root, but by a non-root user holding a narrow sudo delegation to run commands as that account, causing ownership of / to change and resulting in severe denial of service (SSH, sudo, and package-manager failures). The change does not grant write access to / (which ships with restrictive 0555 permissions on RHEL), so the impact is availability loss rather than further privilege escalation.
CVSS v3.1
Affected software
pkg:deb/ubuntu/samba@2:4.3.11+dfsg-0ubuntu0.14.04.20+esm15?arch=source&distro=esm-infra-legacy/trustypkg:deb/ubuntu/samba@2:4.3.11+dfsg-0ubuntu0.16.04.34+esm4?arch=source&distro=esm-infra/xenialpkg:deb/ubuntu/samba@2:4.7.6+dfsg~ubuntu-0ubuntu2.29+esm3?arch=source&distro=esm-infra/bionicpkg:deb/ubuntu/samba@2:4.15.13+dfsg-0ubuntu0.20.04.8+esm2?arch=source&distro=esm-infra/focalpkg:deb/ubuntu/samba@2:4.15.13+dfsg-0ubuntu1.13?arch=source&distro=jammypkg:deb/ubuntu/samba@2:4.19.5+dfsg-4ubuntu9.7?arch=source&distro=noblepkg:deb/ubuntu/samba@2:4.23.6+dfsg-1ubuntu2.2?arch=source&distro=resoluteRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- UBUNTU-CVE-2026-15779
- Osv Schema Version
- 1.7.0
- Aliases
- []
- Ecosystems
- ["Ubuntu:Pro:14.04:LTS","Ubuntu:Pro:16.04:LTS","Ubuntu:Pro:18.04:LTS","Ubuntu:Pro:20.04:LTS","Ubuntu:22.04:LTS","Ubuntu:24.04:LTS","Ubuntu:26.04:LTS"]
- Database Specific Severity
- null
- Cvss Version
- 3.1
Threat ID: 6a6942099c2644c7f86cecdc
Added to database: 07/28/2026, 23:58:01 UTC
Last updated: 07/29/2026, 01:16:38 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.