Junglewise Threat Intelligence

CVE-2026-3238: Samba WINS server NULL pointer dereference in Active Directory Domain Controller

CVE-2026-3238 · Severity: high · CVSS 7.5 · Published 2026-06-08

Technologies: Samba. Vendors: Samba.

Executive brief

A security flaw exists in Samba when it is configured as an Active Directory Domain Controller with WINS support enabled. This component helps manage computer names on a network. An attacker can send a specially crafted network message to crash this service, potentially disrupting network name resolution and causing a denial of service for users and systems relying on the domain controller.

Technical details

A NULL pointer dereference vulnerability exists in Samba's WINS server component when configured as an Active Directory Domain Controller. The flaw is located in the protocol handlers for RELEASE and MULTI_HOME_REG packets, which fail to properly validate incoming requests. An unauthenticated remote attacker can exploit this by sending specially crafted UDP packets to the WINS service, triggering a crash. While the service may restart, the ease of exploitation allows for a sustained denial-of-service state. This vulnerability only affects installations where 'wins support = yes' is explicitly enabled in the smb.conf file. Patches are available in versions 4.22.10, 4.23.8, and 4.24.3.

Affected products

  • Samba Samba All versions since 4.0 before 4.22.10, 4.23.8, 4.24.3

Timeline

  • 2026-06-08: disclosed
  • 2026-06-08: advisory
  • 2026-06-08: patched

References

Related threats