Created attachment 19026 [details] original report OpenAI report: Any authenticated Samba AD domain user can modify internal LDB special records such as @MODULES and @PARTITION through LDAP. By replacing the DSDB module chain with a valid stack that omits acl and aclread, a normal account can open a new LDAP connection without directory ACL enforcement and add itself to Domain Admins, Enterprise Admins, and Builtin Administrators. The exploit then restores the normal module loader; the privileged group memberships persist. This was validated against Samba 4.25.0pre1-GIT-2fc21d87fc8 and an out-of-the- box Ubuntu 24.04 package install of Samba 4.19.5+dfsg-4ubuntu9.6. The proposed fix rejects untrusted LDAP operations against internal special DNs at the RootDSE/network trust boundary while preserving trusted internal DSDB access and normal null-base RootDSE discovery. The report includes the specific rootdse, ACL, module-loader, and partition-loader code paths that compose into the takeover.
Created attachment 19029 [details] OpenAI proposed patch
Created attachment 19030 [details] another version of the report
Created attachment 19033 [details] security-bug-16147-master-metze-01.patches.txt This also fixes the problem for me
(In reply to Stefan Metzmacher from comment #3) > Created attachment 19033 [details] > security-bug-16147-master-metze-01.patches.txt > > This also fixes the problem for me Just a very minor nit-pick on the patch: ldb_dn_is_special() treats NULL as non-special, so the additional check is not necessary.
Created attachment 19038 [details] CVE-2026-TODO-SPECIAL-DN-advisory-v1.txt
Created attachment 19053 [details] security-bug-16147-master-metze-02.patches.txt
Created attachment 19054 [details] CVE-2026-TODO-SPECIAL-DN-advisory-v2.txt
Created attachment 19058 [details] CVE-2026-58221 advisory v3 (same as v2, but with CVE number)
Created attachment 19059 [details] Patch for master with CVE numbers
Created attachment 19060 [details] patch for 4.22 For the 4.22, I have added the shared dsdb_audit_operation_human_readable() functions to audit_util.c, but not removed the static operation_human_readable() from audit_log.c. The master patch applies from 4.23.
Created attachment 19061 [details] patch for 4.22 + 4.23 v2
Created attachment 19062 [details] patch for v4.24
(In reply to Douglas Bagnall from comment #10) > The master patch applies from 4.23. from 4.24. 4.23 and 4.22 are the same.
Created attachment 19063 [details] CVE-2026-58221 advisory v4 (same as v2, but with CVE number)
Created attachment 19071 [details] CVE-2026-58221 advisory v5 (same as v4, but with hints regarding dsdb_audit)
adding vendors here. scheduled release 2026-07-28 10:00 UTC.
This bug was referenced in samba v4-23-stable (Release samba-4.23.10): a0081c8117d2a8e394dfc4aacb918e4cfbde6d30 f0880127a6034eeaceda23c9452e22726bc61713
This bug was referenced in samba v4-24-stable (Release samba-4.24.5): 1b3a0a2e981d3a3c67b6bfb43561d7123584a193 75e3ded48f4bd0087abeb9d2403c6147097dfddc
This bug was referenced in samba v4-22-stable (Release samba-4.22.11): ad876ce926a4aa57e22d5772cd8d9c31c63efec2 1b95d0c2b68b464afb66b883f6e07b3002a64346
This bug was referenced in samba v4-22-test: ad876ce926a4aa57e22d5772cd8d9c31c63efec2 1b95d0c2b68b464afb66b883f6e07b3002a64346
This bug was referenced in samba v4-24-test: ba8b65647603aff9c26d0d517af071119b7abab9 3661b112ab649c373d133727bb15066576a66ae6
This bug was referenced in samba v4-23-test: 62c456ff62b303edb6fb143d76dd6b4c1cca6b4a 96b7e948a80b5a7182c27705949e9e523cf85683
This bug was referenced in samba v4-24-test: 1b3a0a2e981d3a3c67b6bfb43561d7123584a193 75e3ded48f4bd0087abeb9d2403c6147097dfddc
This bug was referenced in samba v4-23-test: a0081c8117d2a8e394dfc4aacb918e4cfbde6d30 f0880127a6034eeaceda23c9452e22726bc61713
This bug was referenced in samba master: ac1c8d6ad5747e69987dbec2307943efbbfdec5c 0973b2faa211dd3ccb4c4d86f0b8c62d36f68e9d
This bug was referenced in samba v4-23-stable (Release samba-4.23.11): 62c456ff62b303edb6fb143d76dd6b4c1cca6b4a 96b7e948a80b5a7182c27705949e9e523cf85683
This bug was referenced in samba v4-24-stable (Release samba-4.24.6): ba8b65647603aff9c26d0d517af071119b7abab9 3661b112ab649c373d133727bb15066576a66ae6