<Vulnerability name="CVE-2026-4480">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Important</ThreatSeverity>
    <PublicDate>2026-05-26T13:43:46</PublicDate>
    <Bugzilla id="2452232" url="https://bugzilla.redhat.com/show_bug.cgi?id=2452232" xml:lang="en:us">
samba: Samba: Remote Code Execution in printing subsystem via unescaped job description
    </Bugzilla>
    <CVSS3 status="verified">
        <CVSS3BaseScore>9.0</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-78</CWE>
    <Details xml:lang="en:us" source="Mitre">
A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the "print command" setting via the "%J"
substitution character without escaping shell meta characters. A remote attacker could exploit this vulnerability by sending a specially crafted print job description that contains unescaped shell characters. This could lead to remote code execution on the affected system.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the "print command" setting via the "%J"
substitution character without escaping shell meta characters. A remote attacker could exploit this vulnerability by sending a specially crafted print job description that contains unescaped shell characters. This could lead to remote code execution on the affected system.
    </Details>
    <Statement xml:lang="en:us">
The issue affects the Samba printing subsystem. Red Hat has classified this issue as Important severity rather than Critical.

Print servers configured with ```"printing = cups"``` or ```"printing = iprint"```, and print servers that do not have the ```"%J"``` substitution character in the "print command" setting are not affected.

By default, Red Hat Enterprise Linux ships with Samba configured to use CUPS-based printing ```printing = cups```. Hence, although the vulnerable code is present, it is not exploitable in default RHEL configurations. 

Because exploitation depends on non-default Samba printing configurations and requires use of the %J substitution parameter within print command, the attack complexity is considered High (AC:H), reducing the likelihood of exploitation in standard deployments.
    </Statement>
    <Acknowledgement xml:lang="en:us">
Red Hat would like to thank Arjun Basnet (Securin Labs), John Walker (ZeroPath), and Ron Ben Yizhak (SafeBreach) for reporting this issue.
    </Acknowledgement>
    <Mitigation xml:lang="en:us">
Remove ```"%J"``` from the "print command" in ```smb.conf``` entry.
    </Mitigation>
    <AffectedRelease cpe="cpe:/o:redhat:enterprise_linux:10.2">
        <ProductName>Red Hat Enterprise Linux 10</ProductName>
        <ReleaseDate>2026-06-03T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:22963">RHSA-2026:22963</Advisory>
        <Package name="samba">samba-0:4.23.5-109.el10_2</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/o:redhat:enterprise_linux_eus:10.0">
        <ProductName>Red Hat Enterprise Linux 10.0 Extended Update Support</ProductName>
        <ReleaseDate>2026-06-23T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:28055">RHSA-2026:28055</Advisory>
        <Package name="samba">samba-0:4.21.3-114.el10_0.1</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/o:redhat:enterprise_linux:7">
        <ProductName>Red Hat Enterprise Linux 7 Extended Lifecycle Support</ProductName>
        <ReleaseDate>2026-06-23T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:28132">RHSA-2026:28132</Advisory>
        <Package name="samba">samba-0:4.10.16-26.el7_9.1</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/o:redhat:rhel_els:7">
        <ProductName>Red Hat Enterprise Linux 7 Extended Lifecycle Support</ProductName>
        <ReleaseDate>2026-06-23T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:28132">RHSA-2026:28132</Advisory>
        <Package name="samba">samba-0:4.10.16-26.el7_9.1</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:enterprise_linux:8">
        <ProductName>Red Hat Enterprise Linux 8</ProductName>
        <ReleaseDate>2026-06-03T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:22644">RHSA-2026:22644</Advisory>
        <Package name="samba">samba-0:4.19.4-16.el8_10</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/o:redhat:enterprise_linux:8">
        <ProductName>Red Hat Enterprise Linux 8</ProductName>
        <ReleaseDate>2026-06-03T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:22644">RHSA-2026:22644</Advisory>
        <Package name="samba">samba-0:4.19.4-16.el8_10</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/o:redhat:rhel_aus:8.4">
        <ProductName>Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support</ProductName>
        <ReleaseDate>2026-06-23T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:28058">RHSA-2026:28058</Advisory>
        <Package name="samba">samba-0:4.13.3-12.el8_4.1</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/o:redhat:rhel_eus_long_life:8.4">
        <ProductName>Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On</ProductName>
        <ReleaseDate>2026-06-23T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:28058">RHSA-2026:28058</Advisory>
        <Package name="samba">samba-0:4.13.3-12.el8_4.1</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:rhel_aus:8.6">
        <ProductName>Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support</ProductName>
        <ReleaseDate>2026-06-23T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:28057">RHSA-2026:28057</Advisory>
        <Package name="samba">samba-0:4.15.5-16.el8_6.1</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:rhel_eus_long_life:8.6">
        <ProductName>Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On</ProductName>
        <ReleaseDate>2026-06-23T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:28057">RHSA-2026:28057</Advisory>
        <Package name="samba">samba-0:4.15.5-16.el8_6.1</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:rhel_tus:8.8">
        <ProductName>Red Hat Enterprise Linux 8.8 Telecommunications Update Service</ProductName>
        <ReleaseDate>2026-06-23T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:28056">RHSA-2026:28056</Advisory>
        <Package name="samba">samba-0:4.17.5-7.el8_8.1</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:rhel_e4s:8.8">
        <ProductName>Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions</ProductName>
        <ReleaseDate>2026-06-23T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:28056">RHSA-2026:28056</Advisory>
        <Package name="samba">samba-0:4.17.5-7.el8_8.1</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:enterprise_linux:9">
        <ProductName>Red Hat Enterprise Linux 9</ProductName>
        <ReleaseDate>2026-06-10T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:25049">RHSA-2026:25049</Advisory>
        <Package name="samba">samba-0:4.23.5-10.el9_8</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/o:redhat:enterprise_linux:9">
        <ProductName>Red Hat Enterprise Linux 9</ProductName>
        <ReleaseDate>2026-06-10T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:25049">RHSA-2026:25049</Advisory>
        <Package name="samba">samba-0:4.23.5-10.el9_8</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:rhel_e4s:9.2">
        <ProductName>Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions</ProductName>
        <ReleaseDate>2026-06-23T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:28054">RHSA-2026:28054</Advisory>
        <Package name="samba">samba-0:4.17.5-105.el9_2.5</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:rhel_e4s:9.4">
        <ProductName>Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions</ProductName>
        <ReleaseDate>2026-06-23T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:28053">RHSA-2026:28053</Advisory>
        <Package name="samba">samba-0:4.19.4-105.el9_4.4</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:rhel_eus:9.6">
        <ProductName>Red Hat Enterprise Linux 9.6 Extended Update Support</ProductName>
        <ReleaseDate>2026-06-15T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:25979">RHSA-2026:25979</Advisory>
        <Package name="samba">samba-0:4.21.3-14.el9_6.1</Package>
    </AffectedRelease>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:6">
        <ProductName>Red Hat Enterprise Linux 6</ProductName>
        <FixState>Out of support scope</FixState>
        <PackageName>samba</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:6">
        <ProductName>Red Hat Enterprise Linux 6</ProductName>
        <FixState>Out of support scope</FixState>
        <PackageName>samba4</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openshift:4">
        <ProductName>Red Hat OpenShift Container Platform 4</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>rhcos</PackageName>
    </PackageState>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-4480
https://nvd.nist.gov/vuln/detail/CVE-2026-4480
https://bugzilla.samba.org/show_bug.cgi?id=16033
    </References>
</Vulnerability>