Skip to main content

Description

A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the "print command" setting via the "%J" substitution character without escaping shell meta characters. A remote attacker could exploit this vulnerability by sending a specially crafted print job description that contains unescaped shell characters. This could lead to remote code execution on the affected system.

Severity

CVSS 3.1 · CNA9 CRITICAL
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
SSVC · CISA-ADP
Exploitationnone
Automatableno
Technical impacttotal

Affected Products

VendorProductAffected versions
Red HatRed Hat Enterprise Linux 10
0:4.23.5-109.el10_2 to <* (unaffected)
Red HatRed Hat Enterprise Linux 10.0 Extended Update Support
0:4.21.3-114.el10_0.1 to <* (unaffected)
Red HatRed Hat Enterprise Linux 7 Extended Lifecycle Support
0:4.10.16-26.el7_9.1 to <* (unaffected)
Red HatRed Hat Enterprise Linux 7 Extended Lifecycle Support
0:4.10.16-26.el7_9.1 to <* (unaffected)
Red HatRed Hat Enterprise Linux 8
0:4.19.4-16.el8_10 to <* (unaffected)
Red HatRed Hat Enterprise Linux 8
0:4.19.4-16.el8_10 to <* (unaffected)
Red HatRed Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
0:4.13.3-12.el8_4.1 to <* (unaffected)
Red HatRed Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
0:4.13.3-12.el8_4.1 to <* (unaffected)
Red HatRed Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
0:4.15.5-16.el8_6.1 to <* (unaffected)
Red HatRed Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On
0:4.15.5-16.el8_6.1 to <* (unaffected)
Red HatRed Hat Enterprise Linux 8.8 Telecommunications Update Service
0:4.17.5-7.el8_8.1 to <* (unaffected)
Red HatRed Hat Enterprise Linux 8.8 Update Services for SAP Solutions
0:4.17.5-7.el8_8.1 to <* (unaffected)
Red HatRed Hat Enterprise Linux 9
0:4.23.5-10.el9_8 to <* (unaffected)
Red HatRed Hat Enterprise Linux 9
0:4.23.5-10.el9_8 to <* (unaffected)
Red HatRed Hat Enterprise Linux 9.2 Update Services for SAP Solutions
0:4.17.5-105.el9_2.5 to <* (unaffected)
Red HatRed Hat Enterprise Linux 9.4 Update Services for SAP Solutions
0:4.19.4-105.el9_4.4 to <* (unaffected)
Red HatRed Hat Enterprise Linux 9.6 Extended Update Support
0:4.21.3-14.el9_6.1 to <* (unaffected)
Red HatRed Hat Enterprise Linux 6-
Red HatRed Hat Enterprise Linux 6-
Red HatRed Hat OpenShift Container Platform 4-
Red HatRed Hat OpenShift Container Platform 4-

References

14 Links

Record Details

Published
2026-05-26
Last updated
2026-09-01
Assigner (CNA)
redhat
Credited to
Red Hat would like to thank Arjun Basnet (Securin Labs), John Walker (ZeroPath), and Ron Ben Yizhak (SafeBreach) for reporting this issue.

Related Tool Categories

Tool categories that test for or protect against this vulnerability class.

CVE record data © The MITRE Corporation, used under the CVE Terms of Use. Exploited-in-the-wild data from the CISA Known Exploited Vulnerabilities catalog (CC0). Exploit prediction scores by FIRST EPSS (first.org/epss). This site is not endorsed or certified by MITRE, NVD, CISA, or FIRST.