summary |
shortlog | log |
commit |
commitdiff |
tree
first ⋅ prev ⋅ next
Michael Tokarev [Sat, 2 Apr 2022 16:01:55 +0000 (19:01 +0300)]
ensure libsmbclient.h is being used with LFS enabled
Bug-Debian: https://bugs.debian.org/221618
Forwarded: not-needed
We build samba with LFS (Large File Support) even on 32bits.
This means some types like off_t are 64-bit wide, again,
even on a 32bit host. libsmbclient.h uses off_t in function
prototypes, and thes prototypes muct match those which were
used at samba compile time - if some other source includes
libsmbclient.h without LFS, it'll get wrong prototypes and
the resulting binary will most likely crash when using
libsmbclient functions.
Detect and error-out this at compile time.
We can not do anything with this in the public header since
it is alredy too late to redefine things, since we can't
guarantee we're the first header a program #includes, and
at the time this libsmbclient.h is included, off_t can
already be defined so our (re)define of _FILE_OFFSET_BITS
does nothing already.
Patching libsmbclient.h to use off64_t means client program
should change their off_t to off64_t too when storing
file offsets returning from libsmbclient, so this is not
an option too.
With this change, we will error out even if the user source
does not use any off_t-related functions. Namely, it was ok
to #include <libsmbclient.h> and use smbc_open/smbc_read/
smbc_write/smbc_close without _F_O_B=64, - neither of these
functions uses off_t. smbc_lseek and others doesn't work,
but if a program does not use them anyway, whole thing will
just work even without enabling LFS. Ideally we can probably
check each individual function which is being affected, by
replacing it with #error if sizeof(off_t) < 8. But this
requires quite some hackery...
Gbp-Pq: Name libsmbclient-ensure-lfs-221618.patch
Michael Tokarev [Fri, 24 Jul 2026 13:14:13 +0000 (16:14 +0300)]
samba (2:4.22.10+dfsg-0+deb13u2) trixie-security; urgency=medium
* 2026-jul-sec-update-bug-16039-v4-22-combined.patch:
Jul-2026 samba security update addresses the following defects:
CVE-2026-6949: https://bugzilla.samba.org/show_bug.cgi?id=16083
TSIG packet with crafted name compression can crash internal DNS server
CVE-2026-58224: https://bugzilla.samba.org/show_bug.cgi?id=16085
CTDB: heap OOB read via unchecked packet length fields
CVE-2026-58216: https://bugzilla.samba.org/show_bug.cgi?id=16087
kpasswd service: 6-byte heap OOB read in packet parser
CVE-2026-58218: https://bugzilla.samba.org/show_bug.cgi?id=16115
DNS TKEY negotiation stores unauthenticated GSS contexts
in a fixed FIFO before authentication completes
CVE-2026-58221: https://bugzilla.samba.org/show_bug.cgi?id=16147
authenticated LDAP access to internal LDB special DNs
permits domain takeover
CVE-2026-58222: https://bugzilla.samba.org/show_bug.cgi?id=16148
LDAP Compare filter injection and trusted-request
confusion disclose protected attributes
[dgit import unpatched samba 2:4.22.10+dfsg-0+deb13u2]
Michael Tokarev [Fri, 24 Jul 2026 13:14:13 +0000 (16:14 +0300)]
Import samba_4.22.10+dfsg-0+deb13u2.debian.tar.xz
[dgit import tarball samba 2:4.22.10+dfsg-0+deb13u2 samba_4.22.10+dfsg-0+deb13u2.debian.tar.xz]
Michael Tokarev [Tue, 26 May 2026 12:46:55 +0000 (15:46 +0300)]
Import samba_4.22.10+dfsg.orig.tar.xz
[dgit import orig samba_4.22.10+dfsg.orig.tar.xz]