From: Raspbian automatic forward porter Date: Wed, 29 Jul 2026 11:17:39 +0000 (+0100) Subject: Merge version 2:4.22.10+dfsg-0+deb13u1+rpi1 and 2:4.22.10+dfsg-0+deb13u2 to produce... X-Git-Tag: archive/raspbian/2%4.22.10+dfsg-0+deb13u2+rpi1^0 X-Git-Url: https://dgit.raspbian.org/%22http://www.example.com/cgi/%22/%22http:/www.example.com/cgi/%22?a=commitdiff_plain;h=0b15693b7e7b6706861b5f2ddd142646d6fbd75e;p=samba.git Merge version 2:4.22.10+dfsg-0+deb13u1+rpi1 and 2:4.22.10+dfsg-0+deb13u2 to produce 2:4.22.10+dfsg-0+deb13u2+rpi1 --- 0b15693b7e7b6706861b5f2ddd142646d6fbd75e diff --cc debian/changelog index 3cdd6889,ac7918b3..c7f06981 --- a/debian/changelog +++ b/debian/changelog @@@ -1,9 -1,30 +1,37 @@@ - samba (2:4.22.10+dfsg-0+deb13u1+rpi1) trixie-staging; urgency=medium ++samba (2:4.22.10+dfsg-0+deb13u2+rpi1) trixie-staging; urgency=medium + + [changes brought forward from 2:4.19.1+dfsg-4+rpi1 by Peter Michael Green at Thu, 12 Oct 2023 15:37:21 +0000] + * Link with libatomic on armhf too. + - -- Raspbian forward porter Tue, 21 Jul 2026 10:36:54 +0000 ++ -- Raspbian forward porter Wed, 29 Jul 2026 11:17:39 +0000 ++ + samba (2:4.22.10+dfsg-0+deb13u2) trixie-security; urgency=medium + + * 2026-jul-sec-update-bug-16039-v4-22-combined.patch: + Jul-2026 samba security update addresses the following defects: + + CVE-2026-6949: https://bugzilla.samba.org/show_bug.cgi?id=16083 + TSIG packet with crafted name compression can crash internal DNS server + + CVE-2026-58224: https://bugzilla.samba.org/show_bug.cgi?id=16085 + CTDB: heap OOB read via unchecked packet length fields + + CVE-2026-58216: https://bugzilla.samba.org/show_bug.cgi?id=16087 + kpasswd service: 6-byte heap OOB read in packet parser + + CVE-2026-58218: https://bugzilla.samba.org/show_bug.cgi?id=16115 + DNS TKEY negotiation stores unauthenticated GSS contexts + in a fixed FIFO before authentication completes + + CVE-2026-58221: https://bugzilla.samba.org/show_bug.cgi?id=16147 + authenticated LDAP access to internal LDB special DNs + permits domain takeover + + CVE-2026-58222: https://bugzilla.samba.org/show_bug.cgi?id=16148 + LDAP Compare filter injection and trusted-request + confusion disclose protected attributes + + -- Michael Tokarev Fri, 24 Jul 2026 16:14:13 +0300 samba (2:4.22.10+dfsg-0+deb13u1) trixie; urgency=medium