CVE-2026-15779

NameCVE-2026-15779
DescriptionA flaw was found in samba's pam_winbind. When mkhomedir is enabled, pam_winbind chowns the target account's home directory without validating the path is not a critical system directory such as /. On affected systems, accounts with / as their home directory (a common default for system accounts) can have this triggered not only by root, but by a non-root user holding a narrow sudo delegation to run commands as that account, causing ownership of / to change and resulting in severe denial of service (SSH, sudo, and package-manager failures). The change does not grant write access to / (which ships with restrictive 0555 permissions on RHEL), so the impact is availability loss rather than further privilege escalation.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
samba (PTS)bullseye2:4.13.13+dfsg-1~deb11u6vulnerable
bullseye (security)2:4.13.13+dfsg-1~deb11u8vulnerable
bookworm, bookworm (security)2:4.17.12+dfsg-0+deb12u4vulnerable
trixie2:4.22.10+dfsg-0+deb13u1vulnerable
trixie (security)2:4.22.10+dfsg-0+deb13u2vulnerable
forky, sid2:4.24.5+dfsg-1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
sambasource(unstable)(unfixed)

Notes

[bookworm] - samba <postponed> (Minor issue; pam_winbind mkhomedir chowns a pre-existing home dir, and mkhomedir is not enabled by default in Debian; can be fixed in next update)
[bullseye] - samba <postponed> (Minor issue; pam_winbind mkhomedir chowns a pre-existing home dir, and mkhomedir is not enabled by default in Debian; can be fixed in next update)
https://bugzilla.redhat.com/show_bug.cgi?id=2499991
check if Red Hat specific

Search for package or bug name: Reporting problems