samba.git
3 months agosamba (2:4.22.10+dfsg-0+deb13u1) trixie; urgency=medium
Michael Tokarev [Tue, 26 May 2026 12:46:55 +0000 (15:46 +0300)]
samba (2:4.22.10+dfsg-0+deb13u1) trixie; urgency=medium

  * switch to actual upstream release for the May-2026 security fixes:

  * This is a security release in order to address the following defects:

    CVE-2026-1933: Missing access checks on reparse point operations
      On a share marked "read only = yes" and on file handles opened R/O users
      can set or delete the reparse point xattrs on files that the user has
      write-access in the file system for.
      https://www.samba.org/samba/security/CVE-2026-1933.html

    CVE-2026-2340: WORM vfs module does not block overwrites
      The WORM (Write-Once, Read Many) vfs module is supposed to lock write
      access to shared files, so they cannot be altered after initial writes.
      It was allowing files to be overwritten by renaming a newly created file
      over a protected file.
      https://www.samba.org/samba/security/CVE-2026-2340.html

    CVE-2026-3012: auto-enrolment GPO installing CA certificate over http
      without verification
      To bootstrap a certificate chain a domain member must fetch a certificate
      without TLS. It was trusting HTTP for this when a more secure encrypted
      LDAP channel was also available.
      https://www.samba.org/samba/security/CVE-2026-3012.html

    CVE-2026-3238: Denial of service against AD DC WINS server
      The WINS server component of the Active Directory Domain controller code
      in Samba is vulnerable to a NULL pointer dereference and crash caused by
      an unauthenticated UDP packet.
      https://www.samba.org/samba/security/CVE-2026-3238.html

    CVE-2026-4408: Unauthenticated Remote Code Execution in Samba DCE/RPC
      SAMR server
      Samba file servers and classic (non-AD) domain controllers with
      samba-dcerpcd started as a system service and with a "check password
      script" that has the %u substitution character are vulnerable to a
      remote code execution.
      https://www.samba.org/samba/security/CVE-2026-4408.html

    CVE-2026-4480: Unauthenticated Remote Code Execution in Samba
      printing subsystem
      Samba print servers with a "print command" that has the %J substitution
      character are vulnerable to a Remote Code Execution.
      https://www.samba.org/samba/security/CVE-2026-4480.html

[dgit import unpatched samba 2:4.22.10+dfsg-0+deb13u1]

3 months agoImport samba_4.22.10+dfsg.orig.tar.xz
Michael Tokarev [Tue, 26 May 2026 12:46:55 +0000 (15:46 +0300)]
Import samba_4.22.10+dfsg.orig.tar.xz

[dgit import orig samba_4.22.10+dfsg.orig.tar.xz]

3 months agoImport samba_4.22.10+dfsg-0+deb13u1.debian.tar.xz
Michael Tokarev [Tue, 26 May 2026 12:46:55 +0000 (15:46 +0300)]
Import samba_4.22.10+dfsg-0+deb13u1.debian.tar.xz

[dgit import tarball samba 2:4.22.10+dfsg-0+deb13u1 samba_4.22.10+dfsg-0+deb13u1.debian.tar.xz]