CVE-2026-2340: Samba: vfs_worm does not block directory modification
A flaw was found in Samba’s vfsworm module. The module is intended to provide write-once, read-many (WORM) protections by preventing modification of files after a configurable grace period. Due to insufficient validation during rename operations, an authenticated user with write access to a share could overwrite a protected file by renaming a newly created file over the existing WORM-protected file.
Other sources
Samba: vfsworm does not block directory modification
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/sambato a version that resolves this vulnerability.Fixed in 2:4.17.12+dfsg-0+deb12u4Fixed in 2:4.22.8+dfsg-0+deb13u2Fixed in 2:4.24.3+dfsg-1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2340?
The severity of CVE-2026-2340 is rated as medium with a score of 6.5.
How do I fix CVE-2026-2340?
To fix CVE-2026-2340, ensure that you update Samba to a version that addresses this vulnerability.
What systems are affected by CVE-2026-2340?
CVE-2026-2340 affects Red Hat Enterprise Linux, Debian Samba, Red Hat OpenShift Container Platform, and Samba itself.
What does CVE-2026-2340 exploit?
CVE-2026-2340 exploits a flaw in the vfs_worm module of Samba, allowing authorized users to modify files after the grace period.
What type of impact can CVE-2026-2340 have?
CVE-2026-2340 can lead to unauthorized file modifications, compromising the integrity of stored data.