Summary:
An update for samba is now available for EulerOS V2.0SP10(x86_64)
EulerOS Security has rated this update as having a security impact of Critical.A Common Vunlnerability Scoring System(CVSS)base score, which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.General:
Samba is the standard Windows interoperability suite of programs for Linux and Unix.
Security Fix(es):
A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the "print command" setting via the "%J" substitution character without escaping shell meta characters. A remote attacker could exploit this vulnerability by sending a specially crafted print job description that contains unescaped shell characters. This could lead to remote code execution on the affected system.(CVE-2026-4480)
A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password script" feature. If this script is configured with the %u substitution character, the client-controlled username is passed without proper escaping of shell meta-characters. This vulnerability allows an attacker to achieve remote command execution on the affected system. This issue primarily affects non-standard configurations where the "check password script" is used with %u and the samba-dcerpcd service is started as a system service.(CVE-2026-4408)Legal Disclaimer:
This document is provided on an "AS IS" basis and does not imply any kind of guarantee or warranty, either express or implied, including the warranties of merchantability or fitness for a particular purpose. In no event shall Huawei or any of its directly or indirectly controlled subsidiaries or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special...
4.11.12-3.h27.r3.eulerosv2r104.11.12-3.h27.r3.eulerosv2r104.11.12-3.h27.r3.eulerosv2r104.11.12-3.h27.r3.eulerosv2r104.11.12-3.h27.r3.eulerosv2r104.11.12-3.h27.r3.eulerosv2r104.11.12-3.h27.r3.eulerosv2r104.11.12-3.h27.r3.eulerosv2r104.11.12-3.h27.r3.eulerosv2r104.11.12-3.h27.r3.eulerosv2r10Exploitability
AV:NAC:LPR:NUI:NScope
S:UImpact
C:NI:NA:H9.8/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H