Red Hat Enterprise Linux 10 vulnerability

A flaw was found in Samba’s handling of NTFS-style reparse points on shares configured with read only = yes. Due to missing SMB-layer access checks, authenticated users with underlying filesystem write permissions may create or delete reparse point metadata through SMB operations even on read-only exports. This could allow modification of SMB-visible file behavior, including converting files into symbolic links or other reparse point types.

Published 27 May 2026Updated 17 Sep 202645 sources
CVSS 7.1

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.