July 2026 samba security fixes for v4.22
Origin: upstream, https://bugzilla.samba.org/show_bug.cgi?id=16039
Forwarded: not-needed
From
ea7530366da502e0a116467e4565304603eba5b1 Mon Sep 17 00:00:00 2001
From: Stefan Metzmacher <metze@samba.org>
Date: Fri, 29 May 2026 12:43:13 +0200
Subject: [PATCH 01/23] CVE-2026-6949: ndr_dns: let ndr_pull_dns_res_rec()
remember the start offset
In order to verify TSIG signatures we need a reliable way to
truncate the original dns_name_packet buffer before the
last additional dns_res_rec.
BUG: https://bugzilla.samba.org/show_bug.cgi?id=16083
Signed-off-by: Stefan Metzmacher <metze@samba.org>
Reviewed-by: Douglas Bagnall <dbagnall@samba.org>
Gbp-Pq: Name 2026-jul-sec-update-bug-16039-v4-22-combined.patch