- samba (2:4.22.10+dfsg-0+deb13u1+rpi1) trixie-staging; urgency=medium
++samba (2:4.22.10+dfsg-0+deb13u2+rpi1) trixie-staging; urgency=medium
+
+ [changes brought forward from 2:4.19.1+dfsg-4+rpi1 by Peter Michael Green <plugwash@raspbian.org> at Thu, 12 Oct 2023 15:37:21 +0000]
+ * Link with libatomic on armhf too.
+
- -- Raspbian forward porter <root@raspbian.org> Tue, 21 Jul 2026 10:36:54 +0000
++ -- Raspbian forward porter <root@raspbian.org> Wed, 29 Jul 2026 11:17:39 +0000
++
+ samba (2:4.22.10+dfsg-0+deb13u2) trixie-security; urgency=medium
+
+ * 2026-jul-sec-update-bug-16039-v4-22-combined.patch:
+ Jul-2026 samba security update addresses the following defects:
+
+ CVE-2026-6949: https://bugzilla.samba.org/show_bug.cgi?id=16083
+ TSIG packet with crafted name compression can crash internal DNS server
+
+ CVE-2026-58224: https://bugzilla.samba.org/show_bug.cgi?id=16085
+ CTDB: heap OOB read via unchecked packet length fields
+
+ CVE-2026-58216: https://bugzilla.samba.org/show_bug.cgi?id=16087
+ kpasswd service: 6-byte heap OOB read in packet parser
+
+ CVE-2026-58218: https://bugzilla.samba.org/show_bug.cgi?id=16115
+ DNS TKEY negotiation stores unauthenticated GSS contexts
+ in a fixed FIFO before authentication completes
+
+ CVE-2026-58221: https://bugzilla.samba.org/show_bug.cgi?id=16147
+ authenticated LDAP access to internal LDB special DNs
+ permits domain takeover
+
+ CVE-2026-58222: https://bugzilla.samba.org/show_bug.cgi?id=16148
+ LDAP Compare filter injection and trusted-request
+ confusion disclose protected attributes
+
+ -- Michael Tokarev <mjt@tls.msk.ru> Fri, 24 Jul 2026 16:14:13 +0300
samba (2:4.22.10+dfsg-0+deb13u1) trixie; urgency=medium