Samba Vulnerability in NTFS-Style Reparse Points in Read-Only Shares
CVE-2026-1933
Key Information:
What is CVE-2026-1933?
A security issue exists in Samba related to its handling of NTFS-style reparse points on shares configured with read-only permissions. This flaw enables authenticated users with write access on the underlying filesystem to create or modify reparse point metadata via SMB operations, even when the shares are set to read-only. As a result, it may lead to unintended alterations in file behavior visible through SMB, potentially allowing files to be transformed into symbolic links or other types of reparse points, which can pose significant security risks.
Affected Version(s)
Red Hat Enterprise Linux 10 0:4.23.5-109.el10_2
Red Hat Enterprise Linux 10.0 Extended Update Support 0:4.21.3-114.el10_0.1
Red Hat Enterprise Linux 8 0:4.19.4-16.el8_10
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved