CVE-2026-2340

Discovered by AISLEPUBLISHEDCWE-280

Description

A flaw was found in Samba’s vfs_worm module. The module is intended to provide write-once, read-many (WORM) protections by preventing modification of files after a configurable grace period. Due to insufficient validation during rename operations, an authenticated user with write access to a share could overwrite a protected file by renaming a newly created file over the existing WORM-protected file.

CVSS Base Scores

CVSS v3.1(Primary)
6.5

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Affected Products

VendorProductVersionStatus
Red HatRed Hat Enterprise Linux 100:4.23.5-109.el10_2unaffected
Red HatRed Hat Enterprise Linux 10.0 Extended Update Support0:4.21.3-114.el10_0.1unaffected
Red HatRed Hat Enterprise Linux 80:4.19.4-16.el8_10unaffected
Red HatRed Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support0:4.15.5-16.el8_6.1unaffected
Red HatRed Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On0:4.15.5-16.el8_6.1unaffected
Red HatRed Hat Enterprise Linux 8.8 Telecommunications Update Service0:4.17.5-7.el8_8.1unaffected
Red HatRed Hat Enterprise Linux 8.8 Update Services for SAP Solutions0:4.17.5-7.el8_8.1unaffected
Red HatRed Hat Enterprise Linux 90:4.23.5-10.el9_8unaffected
Red HatRed Hat Enterprise Linux 9.2 Update Services for SAP Solutions0:4.17.5-105.el9_2.5unaffected
Red HatRed Hat Enterprise Linux 9.4 Update Services for SAP Solutions0:4.19.4-105.el9_4.4unaffected
Red HatRed Hat Enterprise Linux 9.6 Extended Update Support0:4.21.3-14.el9_6.1unaffected
Red HatRed Hat OpenShift Container Platform 4.12412.86.202608241157-0unaffected
Red HatRed Hat OpenShift Container Platform 4.12412.86.202609082051-0unaffected
Red HatRed Hat OpenShift Container Platform 4.13413.92.202609080414-0unaffected
Red HatRed Hat OpenShift Container Platform 4.14414.92.202608172040-0unaffected
Red HatRed Hat OpenShift Container Platform 4.14414.92.202609011250-0unaffected
Red HatRed Hat OpenShift Container Platform 4.15415.92.202608180329-0unaffected
Red HatRed Hat OpenShift Container Platform 4.15415.92.202609140326-0unaffected
Red HatRed Hat OpenShift Container Platform 4.16416.94.202608150307-0unaffected
Red HatRed Hat OpenShift Container Platform 4.16416.94.202609011112-0unaffected
Red HatRed Hat OpenShift Container Platform 4.17417.94.202608250221-0unaffected
Red HatRed Hat OpenShift Container Platform 4.17417.94.202609191027-0unaffected
Red HatRed Hat OpenShift Container Platform 4.18418.94.202608142238-0unaffected
Red HatRed Hat OpenShift Container Platform 4.18418.94.202609031320-0unaffected
Red HatRed Hat OpenShift Container Platform 4.194.19.9.6.202606241344-0unaffected
Red HatRed Hat Enterprise Linux 6——
Red HatRed Hat Enterprise Linux 7——
Red HatRed Hat OpenShift Container Platform 4——

Credits

  • Red Hat would like to thank Pavel Kohout (Aisle Research) for reporting this issue.

References