---
title: "CVE-2026-3238\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2026-3238?format=md
keywords: index, follow
---

# CVE-2026-3238

Publication date 26 May 2026

Last updated 18 June 2026

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**7.5 · High**

[Score breakdown](https://ubuntu.com/security/CVE-2026-3238?format=md#impact-score)

Toggle side navigation

## Description

A flaw was found in Samba’s WINS server component when running as an Active
Directory Domain Controller. The WINS protocol handlers for certain request
types did not properly validate incoming packets, allowing an
unauthenticated remote attacker to trigger a NULL pointer dereference and
crash the WINS service using specially crafted UDP packets.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2026-3238?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| samba | 26.04 LTS resolute | Fixed 2:4.23.6+dfsg-1ubuntu2.1 |
| 25.10 questing | Fixed 2:4.22.3+dfsg-4ubuntu2.4 |
| 24.04 LTS noble | Fixed 2:4.19.5+dfsg-4ubuntu9.6 |
| 22.04 LTS jammy | Fixed 2:4.15.13+dfsg-0ubuntu1.12 |
| 20.04 LTS focal | Fixed 2:4.15.13+dfsg-0ubuntu0.20.04.8+esm2  Ubuntu Pro |
| 18.04 LTS bionic | Ignored changes too intrusive |
| 16.04 LTS xenial | Ignored end of ESM support, was needs-triage |
| 14.04 LTS trusty | Ignored changes too intrusive |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

### Get expanded security coverage with Ubuntu Pro

Reduce your average CVE exposure time from 98 days to 1 day with expanded CVE patching, ten-years security maintenance and optional support for the full stack of open-source applications. Free for personal use.

[Get Ubuntu Pro](https://ubuntu.com/pro)
[30-day free trial](https://ubuntu.com/pro/free-trial)

## Notes

---

### [mdeslaur](https://launchpad.net/~mdeslaur)

This issue only affects configurations where the wins server was
enabled with the "wins support = Yes" option.

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

7.5 · High

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Network |
  | Attack complexity | Low |
  | Privileges required | None |
  | User interaction | None |
  | Scope | Unchanged |
  | Confidentiality impact | None |
  | Integrity impact | None |
  | Availability impact | High |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 7.5 · High |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3238)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2026-3238)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2026-3238)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2026-3238)

### Related Ubuntu Security Notices (USN)

+ [USN-8306-1](https://usn.ubuntu.com/USN-8306-1)
+ Samba vulnerabilities
+ 26 May 2026

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2026-3238>
