CVE-2026-2340

Publication date 26 May 2026

Last updated 2 June 2026


Ubuntu priority

Cvss 3 Severity Score

6.5 · Medium

Score breakdown

Description

WORM vfs module does not block overwrites

Read the notes from the security team

Status

Package Ubuntu Release Status
samba 26.04 LTS resolute
Fixed 2:4.23.6+dfsg-1ubuntu2.1
25.10 questing
Fixed 2:4.22.3+dfsg-4ubuntu2.4
24.04 LTS noble
Fixed 2:4.19.5+dfsg-4ubuntu9.6
22.04 LTS jammy
Fixed 2:4.15.13+dfsg-0ubuntu1.12
20.04 LTS focal
Needs evaluation
18.04 LTS bionic
Needs evaluation
16.04 LTS xenial
Needs evaluation
14.04 LTS trusty
Needs evaluation

Notes


mdeslaur

Per upstream "The vfs_worm module was added in 4.2 (2015), but was found to be insufficient (see https://bugzilla.samba.org/show_bug.cgi?id=10430). It was largely repaired for Samba 4.20, but this bug remained." Only affects configurations where vfs_worm is enabled, which is not the default.

Severity score breakdown

Parameter Value
Base score 6.5 · Medium
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Scope Unchanged
Confidentiality None
Integrity impact High
Availability impact None
Vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

References

Related Ubuntu Security Notices (USN)

Other references


Access our resources on patching vulnerabilities