REDHAT-BUG-2479762: High severity Samba Samba vulnerability

Published May 19, 2026
·
Updated

Samba file servers and classic (non-AD) domain controllers offer the SamValidatePasswordChange and SamValidatePasswordReset RPC services on the SAMR DCE/RPC service when running over NCACNIPTCP. Both services pass a username and password to the "check password script" that can be configured in smb.conf.

If the "check password script" is configured with the %u substitution character, the client-controlled username is passed to the "check password script" without escaping shell meta-characters, leading to a remote command execution vulnerability.

This is a non-standard configuration in several ways:

It affects Samba file servers and classic (non-AD) domain controllers that have the "check password script" configured with the %u substitution character. Active Directory Domain Controllers are not affected, they do not expand the username via the %u substitution character.

The problem is much less dangerous if %u has single quotes directly around it, e.g. '%u', but it's still possible to inject command line options.

Standard Samba file servers and classic domain controllers are also only affected if the samba-dcerpcd service is started as a system service, which can only happen if "rpc start on demand helpers" is set to the non-default setting "no". In the default configuration for DCE/RPC, smbd starts the samba-dcerpcd in a way that makes the vulnerable code inaccessible.

Affected Software

1 affected component
Samba Samba

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Ensure the non-default setting "rpc start on demand helpers" is set to "no" so that the "samba-dcerpcd" service is not started as a system service (the text states the vulnerability is only exploitable when samba-dcerpcd is started as a system service, which can happen only if this setting is set to enable it).

    Samba (smb.conf) / samba-dcerpcd RPC services rpc start on demand helpers = no
  2. Configuration

    If the "check password script" is configured with "%u", modify the script or configuration so that the client-controlled username is passed to the script without expanding/allowing shell meta-character injection (the text states the issue requires "check password script" configured with %u and "without escaping shell meta-characters").

    Samba (smb.conf) "check password script" %u escaping = escape shell meta-characters in the %u-substituted username
  3. Compensating control

    If possible, avoid exposing the vulnerable RPC services to untrusted clients (the text says access is over DCE/RPC running over NCACN_IP_TCP); restrict network access to the affected Samba file servers/classic domain controllers and AD DCs handling these RPC services.

Event History

May 19, 2026
Data Sourced
via Red Hat·09:27 AM
DescriptionSeverityAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of REDHAT-BUG-2479762?

The severity of REDHAT-BUG-2479762 is classified as high with a score of 7.

2

What is the impact of REDHAT-BUG-2479762?

REDHAT-BUG-2479762 affects Samba file servers and classic domain controllers, potentially allowing unauthorized password change and reset operations.

3

How do I fix REDHAT-BUG-2479762?

To fix REDHAT-BUG-2479762, it is recommended to apply the available security updates for Samba.

4

What are the affected software versions for REDHAT-BUG-2479762?

REDHAT-BUG-2479762 affects certain versions of the Samba software that provide RPC services.

5

What services are vulnerable in REDHAT-BUG-2479762?

The vulnerable services in REDHAT-BUG-2479762 are SamValidatePasswordChange and SamValidatePasswordReset RPC services.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203