Amazon Linux 2 Security Advisory: ALAS2-2026-3493
Advisory Released Date: 2026-07-08
Advisory Updated Date: 2026-07-08
unauthenticated udp packet crashes AD DC nbt server (CVE-2026-3238)
Samba file servers and classic (non-AD) domain controllers offer the
SamValidatePasswordChange and SamValidatePasswordReset RPC services on the
SAMR DCE/RPC service when running over NCACN_IP_TCP. Both services pass a
username and password to the "check password script" that can be configured
in smb.conf.
If the "check password script" is configured with the %u
substitution character, the client-controlled username is passed to
the "check password script" without escaping shell meta-characters,
leading to a remote command execution vulnerability.
This is a non-standard configuration in several ways:
It affects Samba file servers and classic (non-AD) domain controllers
that have the "check password script" configured with the %u
substitution character. Active Directory Domain Controllers are not
affected, they do not expand the username via the %u substitution
character.
The problem is much less dangerous if %u has single quotes directly
around it, e.g. '%u', but it's still possible to inject
command line options.
Standard Samba file servers and classic domain controllers are also
only affected if the samba-dcerpcd service is started as a system
service, which can only happen if "rpc start on demand helpers" is set
to the non-default setting "no". In the default configuration for
DCE/RPC, smbd starts the samba-dcerpcd in a way that makes the
vulnerable code inaccessible. (CVE-2026-4408)
Samba passes the client-controlled job description string to the
command configured with the "print command" setting via the "%J"
substitution character without escaping shell meta characters. This
leads to a remote code execution vulnerability.
Print servers configured with "printing = cups" or "printing =
iprint", and print servers that do not have the %J substitution
character in the "print command" setting are not affected.
The problem is much less dangerous if %J has single quotes directly
around it, e.g. '%J', but it's still possible to inject
command line options.
By default, print servers allow guest users to print. (CVE-2026-4480)
Affected Packages:
samba
Note:
This advisory is applicable to Amazon Linux 2 (AL2) Core repository. Visit this FAQ section for the difference between AL2 Core and AL2 Extras advisories.
Issue Correction:
Run yum update samba or yum update --advisory ALAS2-2026-3493 to update your system.
aarch64:
samba-4.10.16-24.amzn2.0.7.aarch64
samba-client-4.10.16-24.amzn2.0.7.aarch64
samba-client-libs-4.10.16-24.amzn2.0.7.aarch64
samba-common-libs-4.10.16-24.amzn2.0.7.aarch64
samba-common-tools-4.10.16-24.amzn2.0.7.aarch64
samba-dc-4.10.16-24.amzn2.0.7.aarch64
samba-dc-libs-4.10.16-24.amzn2.0.7.aarch64
samba-devel-4.10.16-24.amzn2.0.7.aarch64
samba-krb5-printing-4.10.16-24.amzn2.0.7.aarch64
samba-libs-4.10.16-24.amzn2.0.7.aarch64
libsmbclient-4.10.16-24.amzn2.0.7.aarch64
libsmbclient-devel-4.10.16-24.amzn2.0.7.aarch64
libwbclient-4.10.16-24.amzn2.0.7.aarch64
libwbclient-devel-4.10.16-24.amzn2.0.7.aarch64
samba-python-4.10.16-24.amzn2.0.7.aarch64
samba-python-test-4.10.16-24.amzn2.0.7.aarch64
samba-test-4.10.16-24.amzn2.0.7.aarch64
samba-test-libs-4.10.16-24.amzn2.0.7.aarch64
samba-winbind-4.10.16-24.amzn2.0.7.aarch64
samba-winbind-clients-4.10.16-24.amzn2.0.7.aarch64
samba-winbind-krb5-locator-4.10.16-24.amzn2.0.7.aarch64
samba-winbind-modules-4.10.16-24.amzn2.0.7.aarch64
ctdb-4.10.16-24.amzn2.0.7.aarch64
ctdb-tests-4.10.16-24.amzn2.0.7.aarch64
samba-debuginfo-4.10.16-24.amzn2.0.7.aarch64
i686:
samba-4.10.16-24.amzn2.0.7.i686
samba-client-4.10.16-24.amzn2.0.7.i686
samba-client-libs-4.10.16-24.amzn2.0.7.i686
samba-common-libs-4.10.16-24.amzn2.0.7.i686
samba-common-tools-4.10.16-24.amzn2.0.7.i686
samba-dc-4.10.16-24.amzn2.0.7.i686
samba-dc-libs-4.10.16-24.amzn2.0.7.i686
samba-devel-4.10.16-24.amzn2.0.7.i686
samba-krb5-printing-4.10.16-24.amzn2.0.7.i686
samba-libs-4.10.16-24.amzn2.0.7.i686
libsmbclient-4.10.16-24.amzn2.0.7.i686
libsmbclient-devel-4.10.16-24.amzn2.0.7.i686
libwbclient-4.10.16-24.amzn2.0.7.i686
libwbclient-devel-4.10.16-24.amzn2.0.7.i686
samba-python-4.10.16-24.amzn2.0.7.i686
samba-python-test-4.10.16-24.amzn2.0.7.i686
samba-test-4.10.16-24.amzn2.0.7.i686
samba-test-libs-4.10.16-24.amzn2.0.7.i686
samba-winbind-4.10.16-24.amzn2.0.7.i686
samba-winbind-clients-4.10.16-24.amzn2.0.7.i686
samba-winbind-krb5-locator-4.10.16-24.amzn2.0.7.i686
samba-winbind-modules-4.10.16-24.amzn2.0.7.i686
ctdb-4.10.16-24.amzn2.0.7.i686
ctdb-tests-4.10.16-24.amzn2.0.7.i686
samba-debuginfo-4.10.16-24.amzn2.0.7.i686
noarch:
samba-common-4.10.16-24.amzn2.0.7.noarch
samba-pidl-4.10.16-24.amzn2.0.7.noarch
src:
samba-4.10.16-24.amzn2.0.7.src
x86_64:
samba-4.10.16-24.amzn2.0.7.x86_64
samba-client-4.10.16-24.amzn2.0.7.x86_64
samba-client-libs-4.10.16-24.amzn2.0.7.x86_64
samba-common-libs-4.10.16-24.amzn2.0.7.x86_64
samba-common-tools-4.10.16-24.amzn2.0.7.x86_64
samba-dc-4.10.16-24.amzn2.0.7.x86_64
samba-dc-libs-4.10.16-24.amzn2.0.7.x86_64
samba-devel-4.10.16-24.amzn2.0.7.x86_64
samba-vfs-glusterfs-4.10.16-24.amzn2.0.7.x86_64
samba-krb5-printing-4.10.16-24.amzn2.0.7.x86_64
samba-libs-4.10.16-24.amzn2.0.7.x86_64
libsmbclient-4.10.16-24.amzn2.0.7.x86_64
libsmbclient-devel-4.10.16-24.amzn2.0.7.x86_64
libwbclient-4.10.16-24.amzn2.0.7.x86_64
libwbclient-devel-4.10.16-24.amzn2.0.7.x86_64
samba-python-4.10.16-24.amzn2.0.7.x86_64
samba-python-test-4.10.16-24.amzn2.0.7.x86_64
samba-test-4.10.16-24.amzn2.0.7.x86_64
samba-test-libs-4.10.16-24.amzn2.0.7.x86_64
samba-winbind-4.10.16-24.amzn2.0.7.x86_64
samba-winbind-clients-4.10.16-24.amzn2.0.7.x86_64
samba-winbind-krb5-locator-4.10.16-24.amzn2.0.7.x86_64
samba-winbind-modules-4.10.16-24.amzn2.0.7.x86_64
ctdb-4.10.16-24.amzn2.0.7.x86_64
ctdb-tests-4.10.16-24.amzn2.0.7.x86_64
samba-debuginfo-4.10.16-24.amzn2.0.7.x86_64