CVE-2026-2340

Publication date 26 May 2026

Last updated 27 May 2026


Ubuntu priority

Description

WORM vfs module does not block overwrites

Read the notes from the security team

Status

Package Ubuntu Release Status
samba 26.04 LTS resolute
Fixed 2:4.23.6+dfsg-1ubuntu2.1
25.10 questing
Fixed 2:4.22.3+dfsg-4ubuntu2.4
24.04 LTS noble
Fixed 2:4.19.5+dfsg-4ubuntu9.6
22.04 LTS jammy
Fixed 2:4.15.13+dfsg-0ubuntu1.12
20.04 LTS focal
Needs evaluation
18.04 LTS bionic
Needs evaluation
16.04 LTS xenial
Needs evaluation
14.04 LTS trusty
Needs evaluation

Notes


mdeslaur

Per upstream "The vfs_worm module was added in 4.2 (2015), but was found to be insufficient (see https://bugzilla.samba.org/show_bug.cgi?id=10430). It was largely repaired for Samba 4.20, but this bug remained." Only affects configurations where vfs_worm is enabled, which is not the default.

References

Related Ubuntu Security Notices (USN)

Other references


Access our resources on patching vulnerabilities