Description
A flaw was found in Samba’s WINS server component when running as an Active Directory Domain Controller. The WINS protocol handlers for certain request types did not properly validate incoming packets, allowing an unauthenticated remote attacker to trigger a NULL pointer dereference and crash the WINS service using specially crafted UDP packets.
Problem types
Product status
Timeline
| 2026-06-08: | Reported to Red Hat. |
| 2026-05-26: | Made public. |
Credits
Red Hat would like to thank Arad Inbar (DREAM Security Research Team), Ben Grinberg (DREAM Security Research Team), Erez Cohen (DREAM Security Research Team), and Nir Somech (DREAM Security Research Team) for reporting this issue.
References
access.redhat.com/security/cve/CVE-2026-3238
bugzilla.redhat.com/show_bug.cgi?id=2486176 (RHBZ#2486176)
www.samba.org/samba/security/CVE-2026-3238.html