Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-94172.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-94172
Upstream
  • CVE-2026-58218
Published
2026-07-30T14:17:00Z
Modified
2026-09-20T05:32:18Z
Summary
CVE-2026-58218 affecting package samba 4.18.3-2
Details

A flaw was found in Samba's internal DNS server where unauthenticated TKEY registration requests were added to the TKEY name cache before being rejected. A remote, unauthenticated attacker can exploit this behavior by sending a large number of TKEY requests with arbitrary names, exhausting the cache and evicting legitimate TKEY entries. This can prevent legitimate TSIG authentication for signed DNS queries, resulting in a denial of service.

References

Affected packages

Azure Linux:3 / samba

Package

Name
samba
Purl
pkg:rpm/azure-linux/samba

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
4.18.3-2

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-94172.json"