summary |
shortlog | log |
commit |
commitdiff |
tree
first ⋅ prev ⋅ next
Michael Tokarev [Fri, 15 May 2026 03:38:23 +0000 (06:38 +0300)]
samba (2:4.22.8+dfsg-0+deb13u2) trixie-security; urgency=medium
* https://bugzilla.samba.org/show_bug.cgi?id=16018
May-2026 samba security update fixing the following issues:
CVE-2026-1933: Missing access check on reparse point operations
https://bugzilla.samba.org/show_bug.cgi?id=15992
CVE-2026-2340: vfs_worm does not block directory modification
https://bugzilla.samba.org/show_bug.cgi?id=15997
CVE-2026-3012: group policy certificate enrollment uses http://
without validation
https://bugzilla.samba.org/show_bug.cgi?id=16003
CVE-2026-3238: unauthenticated udp packet crashes AD DC nbt server
https://bugzilla.samba.org/show_bug.cgi?id=16012
CVE-2026-4480: Unauthenticated Remote Code Execution using print command
https://bugzilla.samba.org/show_bug.cgi?id=16033
CVE-2026-4408: Remote Code Execution in SAMR when check password script
contains %u substitution placeholder
https://bugzilla.samba.org/show_bug.cgi?id=16034
[dgit import unpatched samba 2:4.22.8+dfsg-0+deb13u2]
Michael Tokarev [Fri, 15 May 2026 03:38:23 +0000 (06:38 +0300)]
Import samba_4.22.8+dfsg-0+deb13u2.debian.tar.xz
[dgit import tarball samba 2:4.22.8+dfsg-0+deb13u2 samba_4.22.8+dfsg-0+deb13u2.debian.tar.xz]
Michael Tokarev [Thu, 19 Feb 2026 12:17:34 +0000 (15:17 +0300)]
Import samba_4.22.8+dfsg.orig.tar.xz
[dgit import orig samba_4.22.8+dfsg.orig.tar.xz]