CVE-2026-58218: Insufficient Resource Pool in Red Hat Red Hat Enterprise Linux 10
CVE-2026-58218 is a medium severity vulnerability in Samba's internal DNS server on Red Hat Enterprise Linux 10. It involves unauthenticated TKEY registration requests being added to the TKEY name cache before rejection, allowing remote attackers to exhaust the cache by sending many arbitrary TKEY requests. This leads to eviction of legitimate TKEY entries and prevents legitimate TSIG authentication for signed DNS queries, causing a denial of service.
AI Analysis
Technical Summary
This vulnerability in Samba's internal DNS server allows remote unauthenticated attackers to send numerous TKEY registration requests with arbitrary names that are cached before being rejected. This cache exhaustion results in eviction of legitimate TKEY entries, disrupting TSIG authentication for signed DNS queries and causing denial of service. The issue affects Red Hat Enterprise Linux 10. No official remediation level or patch information is provided in the vendor advisory.
Potential Impact
The vulnerability causes denial of service by preventing legitimate TSIG authentication for signed DNS queries due to exhaustion and eviction of TKEY cache entries. There is no impact on confidentiality or integrity reported. The CVSS score of 5.3 reflects a medium severity denial of service risk exploitable remotely without authentication.
Mitigation Recommendations
Patch status is not yet confirmed — check the Red Hat advisory at https://access.redhat.com/security/cve/CVE-2026-58218 for current remediation guidance. No official fix or workaround is stated in the provided advisory content. Until a patch is available, monitoring for unusual DNS TKEY request volumes and limiting such traffic may help mitigate impact.
CVE-2026-58218: Insufficient Resource Pool in Red Hat Red Hat Enterprise Linux 10
Description
CVE-2026-58218 is a medium severity vulnerability in Samba's internal DNS server on Red Hat Enterprise Linux 10. It involves unauthenticated TKEY registration requests being added to the TKEY name cache before rejection, allowing remote attackers to exhaust the cache by sending many arbitrary TKEY requests. This leads to eviction of legitimate TKEY entries and prevents legitimate TSIG authentication for signed DNS queries, causing a denial of service.
CVSS v3.1
Score 5.3medium
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability in Samba's internal DNS server allows remote unauthenticated attackers to send numerous TKEY registration requests with arbitrary names that are cached before being rejected. This cache exhaustion results in eviction of legitimate TKEY entries, disrupting TSIG authentication for signed DNS queries and causing denial of service. The issue affects Red Hat Enterprise Linux 10. No official remediation level or patch information is provided in the vendor advisory.
Potential Impact
The vulnerability causes denial of service by preventing legitimate TSIG authentication for signed DNS queries due to exhaustion and eviction of TKEY cache entries. There is no impact on confidentiality or integrity reported. The CVSS score of 5.3 reflects a medium severity denial of service risk exploitable remotely without authentication.
Mitigation Recommendations
Patch status is not yet confirmed — check the Red Hat advisory at https://access.redhat.com/security/cve/CVE-2026-58218 for current remediation guidance. No official fix or workaround is stated in the provided advisory content. Until a patch is available, monitoring for unusual DNS TKEY request volumes and limiting such traffic may help mitigate impact.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- redhat
- Date Reserved
- 2026-06-29T18:13:08.160Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-58218","vendor":"Red Hat"}]
Threat ID: 6a6b5ad09c2644c7f82c543d
Added to database: 07/30/2026, 14:08:16 UTC
Last enriched: 07/30/2026, 14:25:25 UTC
Last updated: 07/30/2026, 14:55:05 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.