Samba: An authenticated user could possibly crash a KDC process.
An out-of-bounds read flaw was found in Samba's Kerberos Key Distribution Center's (KDC) password change (kpasswd) service. When processing malformed ASN.1-encoded Kerberos password change request, Samba server miscalculates the structure size and attempts to read up to six bytes beyond the end of the allocated buffer. While this out-of-bounds read typically results in a harmless decryption failure, if the read hits unmapped memory, it causes the KDC process to crash. An authenticated attacker can send a specially crafted kpasswd request containing malformed ASN.1 data to trigger the out-of-bounds read, which may cause the KDC process to terminate, resulting in a denial of service.
Samba: An authenticated user could possibly crash a KDC process.
Description
An out-of-bounds read flaw was found in Samba's Kerberos Key Distribution Center's (KDC) password change (kpasswd) service. When processing malformed ASN.1-encoded Kerberos password change request, Samba server miscalculates the structure size and attempts to read up to six bytes beyond the end of the allocated buffer. While this out-of-bounds read typically results in a harmless decryption failure, if the read hits unmapped memory, it causes the KDC process to crash. An authenticated attacker can send a specially crafted kpasswd request containing malformed ASN.1 data to trigger the out-of-bounds read, which may cause the KDC process to terminate, resulting in a denial of service.
Affected software
pkg:deb/ubuntu/samba@2:4.3.11+dfsg-0ubuntu0.14.04.20+esm15?arch=source&distro=esm-infra-legacy/trustypkg:deb/ubuntu/samba@2:4.3.11+dfsg-0ubuntu0.16.04.34+esm4?arch=source&distro=esm-infra/xenialpkg:deb/ubuntu/samba@2:4.7.6+dfsg~ubuntu-0ubuntu2.29+esm3?arch=source&distro=esm-infra/bionicpkg:deb/ubuntu/samba@2:4.15.13+dfsg-0ubuntu0.20.04.8+esm2?arch=source&distro=esm-infra/focalpkg:deb/ubuntu/samba@2:4.15.13+dfsg-0ubuntu1.13?arch=source&distro=jammypkg:deb/ubuntu/samba@2:4.19.5+dfsg-4ubuntu9.7?arch=source&distro=noblepkg:deb/ubuntu/samba@2:4.23.6+dfsg-1ubuntu2.2?arch=source&distro=resoluteRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- UBUNTU-CVE-2026-58216
- Osv Schema Version
- 1.7.0
- Ecosystems
- ["Ubuntu:Pro:14.04:LTS","Ubuntu:Pro:16.04:LTS","Ubuntu:Pro:18.04:LTS","Ubuntu:Pro:20.04:LTS","Ubuntu:22.04:LTS","Ubuntu:24.04:LTS","Ubuntu:26.04:LTS"]
Threat ID: 6a6941bb9c2644c7f86af4b6
Added to database: 07/28/2026, 23:56:43 UTC
Last updated: 09/12/2026, 10:01:32 UTC
Views: 78
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.