We received a new security advisory today for the SAMBA software. It concerns the following:
CVE-2026-15779
A vulnerability exists in Samba. The vulnerability arises
from an incorrect permission assignment in "pam_winbind".
If mkhomedir is enabled, pam_winbind changes the owner of the target account's home directory without verifying whether the path is a critical system directory. A local attacker can exploit this vulnerability to perform a denial-of-service attack.
------------------------------
Stefan Martin
------------------------------