SerNet has released SAMBA+ 4.24.5, 4.23.10 and 4.22.11. These security releases address multiple vulnerabilities and should be installed on all affected systems as soon as possible. Updated packages are available for various SUSE and Red Hat platforms as well as for Debian GNU/Linux and Ubuntu. Active Directory domain controllers are the most critical systems and should be updated immediately. SAMBA+ packages for AIX are not affected, as they are built without CTDB or Active Directory support.
The packages address the following issues:
- CVE-2026-6949: TSIG packet with name compression can crash DNS
https://www.samba.org/samba/security/CVE-2026-6949.html - CVE-2026-58216: An authenticated user could possibly crash a KDC process
https://www.samba.org/samba/security/CVE-2026-58216.html - CVE-2026-58218: DNS signing DoS via TKEY name cache exhaustion
https://www.samba.org/samba/security/CVE-2026-58218.html - CVE-2026-58221: Samba AD authenticated LDAP access domain takeover
https://www.samba.org/samba/security/CVE-2026-58221.html - CVE-2026-58222: Samba AD LDAP Compare filter injection and trusted-request confusion disclose protected attributes
https://www.samba.org/samba/security/CVE-2026-58222.html - CVE-2026-58224: The CTDB protocol has bounds checking issues
https://www.samba.org/samba/security/CVE-2026-58224.html
Instructions for package access and upgrading are available in the SAMBA+ How-to collection. If you are upgrading from a SAMBA+ version older than 4.21 and use your own or third-party scripts that rely on Samba’s Python modules, you must install the sernet-samba-python3 package after upgrading on Debian or Ubuntu systems. RHEL and SUSE-based systems are not affected.
SAMBA+ packages are available as software subscriptions in the SAMBA+ shops:
For further questions or to request a quote, please contact us.

