CVE-2026-6949

Publication date 28 July 2026

Last updated 7 August 2026


Ubuntu priority

Description

TSIG packet with name compression can crash DNS. Incorrect size calculations when a TSIG record contains compressed names can lead to a large out-of-bounds write causing the server to crash.

Status

Package Ubuntu Release Status
samba 26.04 LTS resolute
Fixed 2:4.23.6+dfsg-1ubuntu2.2
24.04 LTS noble
Fixed 2:4.19.5+dfsg-4ubuntu9.7
22.04 LTS jammy
Fixed 2:4.15.13+dfsg-0ubuntu1.13
20.04 LTS focal
Needs evaluation
18.04 LTS bionic
Needs evaluation
16.04 LTS xenial
Needs evaluation
14.04 LTS trusty
Needs evaluation

References

Related Ubuntu Security Notices (USN)

Other references


Access our resources on patching vulnerabilities