What is CVE-2026-58218?
A flaw in Samba's internal DNS server allowed unauthenticated TKEY registration requests to be added to the TKEY name cache before rejection. This enables a remote, unauthenticated attacker to exhaust the cache by sending many requests, causing a denial of service. Updating Samba to the latest patched version is recommended.
Azərbaycanca: Samba-nın daxili DNS serverində autentifikasiya olunmamış TKEY qeydiyyat sorğularının rədd edilməzdən əvvəl TKEY ad keşinə əlavə edilməsi qüsuru aşkarlanıb. Bu, autentifikasiya olunmamış uzaqdan hücumçunun çoxsaylı sorğularla keşi doldurmasına imkan verir. Samba-nı ən son təhlükəsizlik yeniləməsinə qaldırmaq tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-400
FAQ2
Which component of Samba is affected by CVE-2026-58218?
It affects Samba's internal DNS server.
What outcome can an attacker achieve by exploiting this vulnerability?
An attacker can cause a denial of service (DoS) by exhausting the TKEY name cache.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.