Project Subscriptions
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-6297-1 | samba security update |
Ubuntu USN |
USN-8306-1 | Samba vulnerabilities |
Solution
No solution given by the vendor.
Workaround
Administrators can mitigate this issue by: Setting read-only permissions on protected files at the underlying filesystem level will prevent modifications. Configuring ```worm:grace_period = 0``` (zero or less) in smb.conf will eliminate the writable grace period (will eliminate the window in which the rename can happen), understanding that this may impact workflows requiring multi-step file creation.
Wed, 27 May 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in Samba’s vfs_worm module. The module is intended to provide write-once, read-many (WORM) protections by preventing modification of files after a configurable grace period. Due to insufficient validation during rename operations, an authenticated user with write access to a share could overwrite a protected file by renaming a newly created file over the existing WORM-protected file. | |
| Title | Samba: vfs_worm does not block directory modification | |
| First Time appeared |
Redhat
Redhat enterprise Linux Redhat openshift |
|
| Weaknesses | CWE-280 | |
| CPEs | cpe:/a:redhat:openshift:4 cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:6 cpe:/o:redhat:enterprise_linux:7 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat enterprise Linux Redhat openshift |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-05-27T13:22:15.957Z
Reserved: 2026-02-11T12:29:16.340Z
Link: CVE-2026-2340
No data.
Status : Awaiting Analysis
Published: 2026-05-27T14:16:44.387
Modified: 2026-05-27T14:54:20.160
Link: CVE-2026-2340
No data.
OpenCVE Enrichment
Updated: 2026-05-27T15:30:27Z
Debian DSA
Ubuntu USN