Out-of-Bounds Read Vulnerability in Samba's KDC Password Change Service
CVE-2026-58216
5.3MEDIUM
What is CVE-2026-58216?
An out-of-bounds read vulnerability exists in Samba's Kerberos Key Distribution Center (KDC) related to the password change service (kpasswd). This flaw arises when the server miscalculates the structure size while processing maliciously crafted ASN.1-encoded password change requests. If exploited, it may result in an attempt to read beyond the allocated memory buffer, potentially leading to a crash of the KDC process. While this generally leads to decryption issues, it can also trigger a denial of service condition if the out-of-bounds read interacts with unmapped memory.
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Tristan Madani (@TristanInSec) (Talence Security) for reporting this issue.