Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-89145.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-89145
Upstream
  • CVE-2026-2340
Published
2026-05-27T14:16:44Z
Modified
2026-09-01T05:26:35Z
Summary
CVE-2026-2340 affecting package samba 4.18.3-2
Details

A flaw was found in Samba’s vfs_worm module. The module is intended to provide write-once, read-many (WORM) protections by preventing modification of files after a configurable grace period. Due to insufficient validation during rename operations, an authenticated user with write access to a share could overwrite a protected file by renaming a newly created file over the existing WORM-protected file.

References

Affected packages

Azure Linux:3 / samba

Package

Name
samba
Purl
pkg:rpm/azure-linux/samba

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
4.18.3-2

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-89145.json"