- samba (2:4.22.8+dfsg-0+deb13u1+rpi1) trixie-staging; urgency=medium
++samba (2:4.22.8+dfsg-0+deb13u2+rpi1) trixie-staging; urgency=medium
+
+ [changes brought forward from 2:4.19.1+dfsg-4+rpi1 by Peter Michael Green <plugwash@raspbian.org> at Thu, 12 Oct 2023 15:37:21 +0000]
+ * Link with libatomic on armhf too.
+
- -- Raspbian forward porter <root@raspbian.org> Wed, 18 Mar 2026 03:55:31 +0000
++ -- Raspbian forward porter <root@raspbian.org> Thu, 28 May 2026 19:06:42 +0000
++
+ samba (2:4.22.8+dfsg-0+deb13u2) trixie-security; urgency=medium
+
+ * https://bugzilla.samba.org/show_bug.cgi?id=16018
+ May-2026 samba security update fixing the following issues:
+ CVE-2026-1933: Missing access check on reparse point operations
+ https://bugzilla.samba.org/show_bug.cgi?id=15992
+ CVE-2026-2340: vfs_worm does not block directory modification
+ https://bugzilla.samba.org/show_bug.cgi?id=15997
+ CVE-2026-3012: group policy certificate enrollment uses http://
+ without validation
+ https://bugzilla.samba.org/show_bug.cgi?id=16003
+ CVE-2026-3238: unauthenticated udp packet crashes AD DC nbt server
+ https://bugzilla.samba.org/show_bug.cgi?id=16012
+ CVE-2026-4480: Unauthenticated Remote Code Execution using print command
+ https://bugzilla.samba.org/show_bug.cgi?id=16033
+ CVE-2026-4408: Remote Code Execution in SAMR when check password script
+ contains %u substitution placeholder
+ https://bugzilla.samba.org/show_bug.cgi?id=16034
+
+ -- Michael Tokarev <mjt@tls.msk.ru> Fri, 15 May 2026 06:38:23 +0300
samba (2:4.22.8+dfsg-0+deb13u1) trixie; urgency=medium