PT-2026-60163 · Samba+1 · Samba+1

·

CVE-2026-15779

·

Published

2026-07-15

·

Updated

2026-08-20

CVSS v3.1

6.1

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
Name of the Vulnerable Software and Affected Versions samba (affected versions not specified)
Description A flaw exists in the pam winbind module of samba. When the mkhomedir feature is enabled, pam winbind changes the ownership of the target account's home directory without verifying if the path is a critical system directory, such as /. In affected environments, system accounts that use / as their home directory can trigger this behavior. This can be initiated by the root user or a non-root user with specific sudo permissions to execute commands as that account. This results in the ownership of / being changed, leading to a severe denial of service that causes failures in SSH, sudo, and package managers. This issue impacts availability rather than allowing privilege escalation, as it does not grant write access to the root directory.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary mitigation, disable the mkhomedir feature in pam winbind.

DoS

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15779
ECHO-9793-9B10-71E9
OESA-2026-3364
OESA-2026-3365
OESA-2026-3410
OESA-2026-3411
OESA-2026-3412
OPENSUSE-SU-2026:21475-1
OPENSUSE-SU-2026:21540-1
SUSE-SU-2026:22977-1
SUSE-SU-2026:23003-1
SUSE-SU-2026:23129-1
SUSE-SU-2026:23152-1
SUSE-SU-2026:3362-1
SUSE-SU-2026:3363-1
SUSE-SU-2026:3364-1
SUSE-SU-2026:3365-1
SUSE-SU-2026:3366-1
SUSE-SU-2026:3367-1
USN-8621-1

Affected Products

Samba
Ubuntu