Linux Distros Unpatched Vulnerability : CVE-2026-58224

critical Nessus Plugin ID 330473

Synopsis

The Linux/Unix host has one or more packages installed with a vulnerability that the vendor indicates will not be patched.

Description

The Linux/Unix host has one or more packages installed that are impacted by a vulnerability without a vendor supplied patch available.

- CTDB fails to do a number of integrity checks on received packets. This includes: * checking of field lengths against packet lengths when unmarshalling packets; * edge-case checking of string NUL-termination;
and * sanity checking of overall packet lengths. This can result in denial of service (DoS) (due to crash or out-of memory) and possible limited disclosure of adjacent memory allocations. Most of the issues are in the protocol handling for the CTDB private network. Some are in handling of the CTDB event protocol, used on a local Unix domain socket. The impact is mitigated by documented protections that should be in place on the CTDB private network: It is strongly recommended that the private addresses are configured on a private network that is separate from client networks. This is because the CTDB protocol is both unauthenticated and unencrypted. [...] Overall sanity checking of packet lengths to avoid out-of-memory DoS is not being addressed. No size limit is currently placed on packets sent by CTDB, so implementing an arbitrary restriction on the size of received packets could result in the rejection of valid packets. Part of the solution to all of these issues is strengthening the documentation about securing the private network. (CVE-2026-58224)

Note that Nessus relies on the presence of the package as reported by the vendor.

Solution

There is no known solution at this time.

See Also

https://security-tracker.debian.org/tracker/CVE-2026-58224

https://ubuntu.com/security/CVE-2026-58224

Plugin Details

Severity: Critical

ID: 330473

File Name: unpatched_CVE_2026_58224.nasl

Version: 1.1

Type: Local

Agent: unix

Family: Misc.

Published: 7/29/2026

Updated: 7/29/2026

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.73

CVSS v2

Risk Factor: Medium

Base Score: 6.4

Temporal Score: 5.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:P

CVSS Score Source: CVE-2026-58224

CVSS v3

Risk Factor: Critical

Base Score: 9.1

Temporal Score: 8.3

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:U/RC:C

Vulnerability Information

CPE: cpe:/o:canonical:ubuntu_linux:14.04:-:lts, cpe:/o:canonical:ubuntu_linux:16.04:-:lts, cpe:/o:canonical:ubuntu_linux:18.04:-:lts, cpe:/o:canonical:ubuntu_linux:20.04:-:lts, cpe:/o:debian:debian_linux:11.0, cpe:/o:debian:debian_linux:12.0, cpe:/o:debian:debian_linux:14.0, p-cpe:/a:canonical:ubuntu_linux:samba, p-cpe:/a:debian:debian_linux:samba

Required KB Items: Host/cpu, Host/local_checks_enabled, global_settings/vendor_unpatched, Host/OS/identifier

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 7/28/2026

Reference Information

CVE: CVE-2026-58224