A flaw was found in Samba’s certificate auto-enrollment Group Policy handling. When certificate auto-enrollment is enabled, Samba may retrieve a CA certificate over an unencrypted HTTP connection and…
高危 CVSS 8.0
摘要
A flaw was found in Samba’s certificate auto-enrollment Group Policy handling. When certificate auto-enrollment is enabled, Samba may retrieve a CA certificate over an unencrypted HTTP connection and install it into the local trust store without proper verification. An attacker with the ability to intercept or redirect network traffic could exploit this behavior to supply a malicious certificate authority certificate, potentially allowing interception or spoofing of trusted communications.
中文摘要建设中,暂以英文摘要呈现(DR-003 v2)。
深度研判
该漏洞尚未生成深度研判报告(DR-003 v2 AI pipeline 建设中)。
受影响产品
- :
数据来源
- NVD DATABASE
原始链接
- https://access.redhat.com/errata/RHSA-2026:22644 Issue Tracking
- https://access.redhat.com/errata/RHSA-2026:22963 Issue Tracking
- https://access.redhat.com/errata/RHSA-2026:25049
- https://access.redhat.com/errata/RHSA-2026:25979
- https://access.redhat.com/errata/RHSA-2026:28053
- https://access.redhat.com/errata/RHSA-2026:28054
- https://access.redhat.com/errata/RHSA-2026:28055
- https://access.redhat.com/errata/RHSA-2026:28056
- https://access.redhat.com/errata/RHSA-2026:28057
- https://access.redhat.com/errata/RHSA-2026:29863
- https://access.redhat.com/security/cve/CVE-2026-3012 Mitigation
- https://bugzilla.redhat.com/show_bug.cgi?id=2447319 Issue Tracking
- https://bugzilla.samba.org/show_bug.cgi?id=16003 Issue Tracking
- https://access.redhat.com/errata/RHSA-2026:22644 Issue Tracking
- https://access.redhat.com/errata/RHSA-2026:22963 Issue Tracking
- https://access.redhat.com/errata/RHSA-2026:25049
- https://access.redhat.com/errata/RHSA-2026:25979
- https://access.redhat.com/errata/RHSA-2026:28053
- https://access.redhat.com/errata/RHSA-2026:28054
- https://access.redhat.com/errata/RHSA-2026:28055
- https://access.redhat.com/errata/RHSA-2026:28056
- https://access.redhat.com/errata/RHSA-2026:28057
- https://access.redhat.com/errata/RHSA-2026:29863
- https://access.redhat.com/security/cve/CVE-2026-3012 Mitigation
- https://bugzilla.redhat.com/show_bug.cgi?id=2447319 Issue Tracking
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-3012.json
时间线
- nvd_ingest NVD