Home

Description

A flaw was found in Samba’s WINS server component when running as an Active Directory Domain Controller. The WINS protocol handlers for certain request types did not properly validate incoming packets, allowing an unauthenticated remote attacker to trigger a NULL pointer dereference and crash the WINS service using specially crafted UDP packets.

PUBLISHED Reserved 2026-02-26 | Published 2026-06-08 | Updated 2026-06-08 | Assigner redhat




HIGH: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Problem types

NULL Pointer Dereference

Product status

Default status
unknown

Default status
unknown

Default status
unknown

Default status
unknown

Default status
unknown

Default status
unknown

Default status
unknown

Timeline

2026-06-08:Reported to Red Hat.
2026-05-26:Made public.

Credits

Red Hat would like to thank Arad Inbar (DREAM Security Research Team), Ben Grinberg (DREAM Security Research Team), Erez Cohen (DREAM Security Research Team), and Nir Somech (DREAM Security Research Team) for reporting this issue.

References

access.redhat.com/security/cve/CVE-2026-3238 vdb-entry

bugzilla.redhat.com/show_bug.cgi?id=2486176 (RHBZ#2486176) issue-tracking

www.samba.org/samba/security/CVE-2026-3238.html

cve.org (CVE-2026-3238)

nvd.nist.gov (CVE-2026-3238)

Download JSON