CVE-2026-15779: Samba-winbind: samba: pam_winbind mkhomedir chowns critical system paths without validation

Published Jul 14, 2026
·
Updated

A flaw was found in samba's pamwinbind module. When pamwinbind.conf sets mkhomedir = yes, the module's pammkhomedir()/pamchownhomedir() functions call chown() on the target account's home directory (pwdir, taken directly from getpwnam()) without validating that the path is not a sensitive system directory. On RHEL, several stock system accounts (e.g. nobody, sssd, nscd) ship with / as their home directory by default in /etc/passwd. Opening a PAM session for such an account causes the root filesystem (/) to be chown'd to that account's uid/gid, breaking ownership checks relied on by sshd (StrictModes), sudo, and package tooling. Reproduced directly in an isolated sandbox using the exact affected NVRs: the trigger is not limited to root explicitly running su - nobody (the originally reported PoC) -- a non-root user holding only a narrow, common sudo delegation (e.g. 'someuser ALL=(nobody) NOPASSWD: ...') reaches the identical code path via the shared system-auth PAM stack included by sudo. Also confirmed: / ships with mode 0555 on RHEL, so the resulting ownership change does not grant the new owner write access to / (no arbitrary file creation/rename/deletion capability is gained); impact is denial of service via broken ownership checks, not privilege escalation via filesystem write access. Per the reporting bug (RHEL-178261), this was discovered during a customer penetration test (SFDC case 04452638). This flaw affects samba versions using the older pamchownhomedir() structure (samba 4.19.x/4.23.x, confirmed via source diff and live reproduction). A fix is gated and confirmed queued for RHEL 8.10.z (RHEL-178261, via RHBA-2026:169544, publishing 2026-07-28), RHEL 9.8.z (RHEL-180756, via RHBA-2026:168497, publishing 2026-08-04), and RHEL 10.2.z (RHEL-180758, via RHBA-2026:168496, publishing 2026-08-04) -- all three are non-security bug-fix errata. RHEL 9.9 and RHEL 10.3 ship samba 4.24.3, which refactored the affected code path upstream (chown() only fires when mkdir() creates a genuinely new directory, not when the target already exists) -- confirmed via live reproduction in isolated sandboxes using the exact NVRs those releases ship (samba-winbind-4.24.3-1.el9 and samba-winbind-4.24.3-100.el10) that neither su nor sudo-delegation triggers the chown. RHEL 9.9/10.3 are NOT AFFECTED.

Other sources

A flaw was found in samba's pamwinbind. When mkhomedir is enabled, pamwinbind chowns the target account's home directory without validating the path is not a critical system directory such as /. On affected systems, accounts with / as their home directory (a common default for system accounts) can have this triggered not only by root, but by a non-root user holding a narrow sudo delegation to run commands as that account, causing ownership of / to change and resulting in severe denial of service (SSH, sudo, and package-manager failures). The change does not grant write access to / (which ships with restrictive 0555 permissions on RHEL), so the impact is availability loss rather than further privilege escalation.

NVD

Affected Software

3 affected components
Samba samba-winbind (pam_winbind)>=4.19.0<=4.23.x
samba-winbind>=4.19.0<=4.23.x
debian/samba<=2:4.13.13+dfsg-1~deb11u6, <=2:4.13.13+dfsg-1~deb11u8, <=2:4.17.12+dfsg-0+deb12u4, <=2:4.22.10+dfsg-0+deb13u1, <=2:4.22.10+dfsg-0+deb13u2, <=2:4.24.5+dfsg-1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade RHEL 8.10.z to a version that resolves this vulnerability.

    Fixed in RHEL-178261Patch RHBA-2026:169544
  2. Upgrade

    Upgrade RHEL 9.8.z to a version that resolves this vulnerability.

    Fixed in RHEL-180756Patch RHBA-2026:168497
  3. Upgrade

    Upgrade RHEL 10.2.z to a version that resolves this vulnerability.

    Fixed in RHEL-180758Patch RHBA-2026:168496
  4. Configuration

    In /etc/security/pam_winbind.conf (pam_winbind.conf), set mkhomedir = no to prevent pam_winbind from calling _pam_mkhomedir()/_pam_chown_homedir() and chown()ing the target account’s home directory (pw_dir) without validating it isn’t a critical system directory like /.

    samba pam_winbind mkhomedir = no

Event History

Jul 14, 2026
Data Sourced
via Red Hat·02:19 PM
DescriptionSeverityAffected Software
Jul 15, 2026
CVE Published
via MITRE·12:33 PM
Data Sourced
via MITRE·12:33 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:17 PM
DescriptionSeverityWeakness
Jul 28, 2026
Data Sourced
via Launchpad·01:08 PM
Description
Aug 1, 2026
Data Sourced
via Debian·01:12 PM
DescriptionAffected Software
Aug 7, 2026
Data Sourced
via Ubuntu·01:16 PM
RemedyDescriptionSeverityAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-15779?

CVE-2026-15779 has a medium severity rating of 6.1.

2

How does CVE-2026-15779 impact Samba's functionality?

CVE-2026-15779 allows pam_winbind to change ownership of critical system paths due to inadequate validation.

3

How can I mitigate CVE-2026-15779?

To mitigate CVE-2026-15779, ensure that pam_winbind is configured to not set mkhomedir to yes or to validate paths properly.

4

Which versions of Samba are affected by CVE-2026-15779?

CVE-2026-15779 affects versions of Samba that include the pam_winbind module.

5

What should I do if I am using a vulnerable version of Samba related to CVE-2026-15779?

If using a vulnerable version of Samba related to CVE-2026-15779, you'll need to update to a patched version or adjust your configuration settings.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203