{
  "threat_severity" : "Moderate",
  "public_date" : "2026-05-27T10:35:47Z",
  "bugzilla" : {
    "description" : "samba: vfs_worm does not block directory modification",
    "id" : "2447318",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2447318"
  },
  "cvss3" : {
    "cvss3_base_score" : "6.5",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N",
    "status" : "verified"
  },
  "cwe" : "CWE-280",
  "details" : [ "A flaw was found in Samba’s vfs_worm module. The module is intended to provide write-once, read-many (WORM) protections by preventing modification of files after a configurable grace period. Due to insufficient validation during rename operations, an authenticated user with write access to a share could overwrite a protected file by renaming a newly created file over the existing WORM-protected file.", "A flaw was found in Samba’s vfs_worm module. The module is intended to provide write-once, read-many (WORM) protections by preventing modification of files after a configurable grace period. Due to insufficient validation during rename operations, an authenticated user with write access to a share could overwrite a protected file by renaming a newly created file over the existing WORM-protected file." ],
  "statement" : "This vulnerability is rated Moderate severity because exploitation requires authenticated write access to a Samba share already configured to permit file creation and modification.\nThe flaw affects the vfs_worm module, which provides additional immutability protections for files after a configurable grace period. Due to improper handling of rename operations, a user with existing write permissions could overwrite files that should have become immutable under the WORM policy.\nThe vulnerability does not bypass underlying filesystem access controls or grant additional privileges beyond those already assigned to the authenticated user. However, because the primary purpose of the vfs_worm module is to protect file integrity, the ability to modify protected files results in a high integrity impact.",
  "acknowledgement" : "Red Hat would like to thank Pavel Kohout (Aisle Research) for reporting this issue.",
  "affected_release" : [ {
    "product_name" : "Red Hat Enterprise Linux 10",
    "release_date" : "2026-06-03T00:00:00Z",
    "advisory" : "RHSA-2026:22963",
    "cpe" : "cpe:/o:redhat:enterprise_linux:10.2",
    "package" : "samba-0:4.23.5-109.el10_2"
  }, {
    "product_name" : "Red Hat Enterprise Linux 10.0 Extended Update Support",
    "release_date" : "2026-06-23T00:00:00Z",
    "advisory" : "RHSA-2026:28055",
    "cpe" : "cpe:/o:redhat:enterprise_linux_eus:10.0",
    "package" : "samba-0:4.21.3-114.el10_0.1"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "release_date" : "2026-06-03T00:00:00Z",
    "advisory" : "RHSA-2026:22644",
    "cpe" : "cpe:/a:redhat:enterprise_linux:8",
    "package" : "samba-0:4.19.4-16.el8_10"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "release_date" : "2026-06-03T00:00:00Z",
    "advisory" : "RHSA-2026:22644",
    "cpe" : "cpe:/o:redhat:enterprise_linux:8",
    "package" : "samba-0:4.19.4-16.el8_10"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
    "release_date" : "2026-06-23T00:00:00Z",
    "advisory" : "RHSA-2026:28057",
    "cpe" : "cpe:/a:redhat:rhel_aus:8.6",
    "package" : "samba-0:4.15.5-16.el8_6.1"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
    "release_date" : "2026-06-23T00:00:00Z",
    "advisory" : "RHSA-2026:28057",
    "cpe" : "cpe:/a:redhat:rhel_eus_long_life:8.6",
    "package" : "samba-0:4.15.5-16.el8_6.1"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
    "release_date" : "2026-06-23T00:00:00Z",
    "advisory" : "RHSA-2026:28056",
    "cpe" : "cpe:/a:redhat:rhel_tus:8.8",
    "package" : "samba-0:4.17.5-7.el8_8.1"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
    "release_date" : "2026-06-23T00:00:00Z",
    "advisory" : "RHSA-2026:28056",
    "cpe" : "cpe:/a:redhat:rhel_e4s:8.8",
    "package" : "samba-0:4.17.5-7.el8_8.1"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "release_date" : "2026-06-10T00:00:00Z",
    "advisory" : "RHSA-2026:25049",
    "cpe" : "cpe:/a:redhat:enterprise_linux:9",
    "package" : "samba-0:4.23.5-10.el9_8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "release_date" : "2026-06-10T00:00:00Z",
    "advisory" : "RHSA-2026:25049",
    "cpe" : "cpe:/o:redhat:enterprise_linux:9",
    "package" : "samba-0:4.23.5-10.el9_8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
    "release_date" : "2026-06-23T00:00:00Z",
    "advisory" : "RHSA-2026:28054",
    "cpe" : "cpe:/a:redhat:rhel_e4s:9.2",
    "package" : "samba-0:4.17.5-105.el9_2.5"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
    "release_date" : "2026-06-23T00:00:00Z",
    "advisory" : "RHSA-2026:28053",
    "cpe" : "cpe:/a:redhat:rhel_e4s:9.4",
    "package" : "samba-0:4.19.4-105.el9_4.4"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.6 Extended Update Support",
    "release_date" : "2026-06-15T00:00:00Z",
    "advisory" : "RHSA-2026:25979",
    "cpe" : "cpe:/a:redhat:rhel_eus:9.6",
    "package" : "samba-0:4.21.3-14.el9_6.1"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4.19",
    "release_date" : "2026-07-02T00:00:00Z",
    "advisory" : "RHSA-2026:29863",
    "cpe" : "cpe:/a:redhat:openshift:4.19::el9",
    "package" : "rhcos-4.19.9.6.202606241344-0"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat Enterprise Linux 6",
    "fix_state" : "Out of support scope",
    "package_name" : "samba",
    "cpe" : "cpe:/o:redhat:enterprise_linux:6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 6",
    "fix_state" : "Out of support scope",
    "package_name" : "samba4",
    "cpe" : "cpe:/o:redhat:enterprise_linux:6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "fix_state" : "Will not fix",
    "package_name" : "samba",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2026-2340\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-2340\nhttps://bugzilla.samba.org/show_bug.cgi?id=15997" ],
  "name" : "CVE-2026-2340",
  "mitigation" : {
    "value" : "Administrators can mitigate this issue by:\nSetting read-only permissions on protected files at the underlying filesystem level will prevent modifications.\nConfiguring ```worm:grace_period = 0``` (zero or less) in smb.conf will eliminate the writable grace period (will eliminate the window in which the rename can happen), understanding that this may impact workflows requiring multi-step file creation.",
    "lang" : "en:us"
  },
  "csaw" : false
}