Samba DNS TKEY Cache DoS via Unauth Reg
CVE-2026-58218 Published on July 30, 2026
Samba: dns signing dos via tkey name cache exhaustion
A flaw was found in Samba's internal DNS server where unauthenticated TKEY registration requests were added to the TKEY name cache before being rejected. A remote, unauthenticated attacker can exploit this behavior by sending a large number of TKEY requests with arbitrary names, exhausting the cache and evicting legitimate TKEY entries. This can prevent legitimate TSIG authentication for signed DNS queries, resulting in a denial of service.
Vulnerability Analysis
CVE-2026-58218 is exploitable with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity, and a small impact on availability.
Timeline
Reported to Red Hat.
Made public. 8 days later.
Weakness Type
Insufficient Resource Pool
The software's resource pool is not large enough to handle peak demand, which allows an attacker to prevent others from accessing the resource by using a (relatively) large number of requests for resources. Frequently the consequence is a "flood" of connection or sessions.
Products Associated with CVE-2026-58218
You can be notified by email with stack.watch whenever vulnerabilities like CVE-2026-58218 are published in these products: