summary |
shortlog | log |
commit |
commitdiff |
tree
first ⋅ prev ⋅ next
Michael Tokarev [Fri, 24 Jul 2026 13:14:13 +0000 (16:14 +0300)]
samba (2:4.22.10+dfsg-0+deb13u2) trixie-security; urgency=medium
* 2026-jul-sec-update-bug-16039-v4-22-combined.patch:
Jul-2026 samba security update addresses the following defects:
CVE-2026-6949: https://bugzilla.samba.org/show_bug.cgi?id=16083
TSIG packet with crafted name compression can crash internal DNS server
CVE-2026-58224: https://bugzilla.samba.org/show_bug.cgi?id=16085
CTDB: heap OOB read via unchecked packet length fields
CVE-2026-58216: https://bugzilla.samba.org/show_bug.cgi?id=16087
kpasswd service: 6-byte heap OOB read in packet parser
CVE-2026-58218: https://bugzilla.samba.org/show_bug.cgi?id=16115
DNS TKEY negotiation stores unauthenticated GSS contexts
in a fixed FIFO before authentication completes
CVE-2026-58221: https://bugzilla.samba.org/show_bug.cgi?id=16147
authenticated LDAP access to internal LDB special DNs
permits domain takeover
CVE-2026-58222: https://bugzilla.samba.org/show_bug.cgi?id=16148
LDAP Compare filter injection and trusted-request
confusion disclose protected attributes
[dgit import unpatched samba 2:4.22.10+dfsg-0+deb13u2]
Michael Tokarev [Fri, 24 Jul 2026 13:14:13 +0000 (16:14 +0300)]
Import samba_4.22.10+dfsg-0+deb13u2.debian.tar.xz
[dgit import tarball samba 2:4.22.10+dfsg-0+deb13u2 samba_4.22.10+dfsg-0+deb13u2.debian.tar.xz]
Michael Tokarev [Tue, 26 May 2026 12:46:55 +0000 (15:46 +0300)]
Import samba_4.22.10+dfsg.orig.tar.xz
[dgit import orig samba_4.22.10+dfsg.orig.tar.xz]