- samba (2:4.24.4+dfsg-1+rpi1) forky-staging; urgency=medium
++samba (2:4.24.6+dfsg-1+rpi1) forky-staging; urgency=medium
+
+ [changes brought forward from 2:4.19.1+dfsg-4+rpi1 by Peter Michael Green <plugwash@raspbian.org> at Thu, 12 Oct 2023 15:37:21 +0000]
+ * Link with libatomic on armhf too.
+
- -- Raspbian forward porter <root@raspbian.org> Tue, 21 Jul 2026 16:18:14 +0000
++ -- Raspbian forward porter <root@raspbian.org> Mon, 07 Sep 2026 21:45:47 +0000
++
+ samba (2:4.24.6+dfsg-1) unstable; urgency=medium
+
+ * debian/upstream/signing-key.asc: update
+ * new upstream stable.bugfix release:
+ - https://bugzilla.samba.org/show_bug.cgi?id=15978:
+ leases torture test flappy (marked flappy)
+ - https://bugzilla.samba.org/show_bug.cgi?id=15994:
+ CTDB doesn't send tickle ACKs when taking over a released IP
+ - https://bugzilla.samba.org/show_bug.cgi?id=16065:
+ Memory leak in DRS when replication fails
+ - https://bugzilla.samba.org/show_bug.cgi?id=16077:
+ witness test flappy needs to be fixed
+ - https://bugzilla.samba.org/show_bug.cgi?id=16093:
+ temporary read of unrelated or non-existing memory in s3 dfs server
+ - https://bugzilla.samba.org/show_bug.cgi?id=16094:
+ source4/dsdb/samdb/cracknames.c doesn't use ldb_binary_encode_string()
+ consistently
+ - https://bugzilla.samba.org/show_bug.cgi?id=16152:
+ CTDB can run nested elections, in rare circumstances
+ - https://bugzilla.samba.org/show_bug.cgi?id=16153:
+ dsgetdcname() may not detect an active directory domain if the
+ netbios domain name is given and nmbd nor the nbt service is available
+ - https://bugzilla.samba.org/show_bug.cgi?id=16176:
+ vfs_ceph_snapshots: smbd panics on snapshot access for a share
+ mounted at the CephFS root ("/")
+ - https://bugzilla.samba.org/show_bug.cgi?id=16186:
+ vfs_ceph_new: smbd crashes when mixing proxy and non-proxy CephFS shares
+ - https://bugzilla.samba.org/show_bug.cgi?id=16191:
+ race condition in pthreadpool when forking
+ - https://bugzilla.samba.org/show_bug.cgi?id=16199:
+ ndr_{push,pull,print}_{timeval,timespec} encode/decode the value twice
+ * d/samba-libs.symbols: add new ndr symbols
+
+ -- Michael Tokarev <mjt@tls.msk.ru> Thu, 13 Aug 2026 19:14:56 +0300
+
+ samba (2:4.24.5+dfsg-1) unstable; urgency=medium
+
+ * new upstream Jul-2026 secrity release, fixing the following issues:
+ CVE-2026-6949: TSIG packet with name compression can crash DNS
+ https://www.samba.org/samba/security/CVE-2026-6949.html
+ CVE-2026-58216: An authenticated user could possibly crash a KDC process
+ https://www.samba.org/samba/security/CVE-2026-58216.html
+ CVE-2026-58218: DNS signing DoS via TKEY name cache exhaustion
+ https://www.samba.org/samba/security/CVE-2026-58218.html
+ CVE-2026-58221: Samba AD authenticated LDAP access domain takeover
+ https://www.samba.org/samba/security/CVE-2026-58221.html
+ CVE-2026-58222: Samba AD LDAP Compare filter injection and
+ trusted-request confusion disclose protected attributes
+ https://www.samba.org/samba/security/CVE-2026-58222.html
+ CVE-2026-58224: The CTDB protocol has bounds checking issues
+ https://www.samba.org/samba/security/CVE-2026-58224.html
+
+ -- Michael Tokarev <mjt@tls.msk.ru> Tue, 28 Jul 2026 14:09:41 +0300
samba (2:4.24.4+dfsg-1) unstable; urgency=medium