Re: [BLFS Trac] #23163: samba-4.24.3 (was: samba-4.24.1)

"BLFS Trac" ([email protected] via blfs-book Mailing List) <[email protected]>
Newsgroups gmane.linux.lfs.beyond.book
Message-ID <[email protected]>
#23163: samba-4.24.3
-------------------------+------------------------------
 Reporter:  Bruce Dubbs  |       Owner:  Douglas R. Reno
     Type:  enhancement  |      Status:  assigned
 Priority:  high         |   Milestone:  13.1
Component:  BOOK         |     Version:  git
 Severity:  normal       |  Resolution:
 Keywords:               |
-------------------------+------------------------------
Changes (by Douglas R. Reno):

 * summary:  samba-4.24.1 => samba-4.24.3

Comment:

 Now 4.24.3.

 {{{
 Release Announcements
 ---------------------

 This is a security release in order to address the following defects:

 o CVE-2026-1933:   Missing access checks on reparse point operations

                    On a share marked "read only = yes" and
                    on file handles opened R/O users can set
                    or delete the reparse point xattrs on files
                    that the user has write-access in the file
                    system for.

                    https://www.samba.org/samba/security/CVE-2026-1933.html


 o CVE-2026-2340:   WORM vfs module does not block overwrites

                    The WORM (Write-Once, Read Many) vfs module
                    is supposed to lock write access to shared
                    files, so they cannot be altered after initial
                    writes. It was allowing files to be overwritten
                    by renaming a newly created file over a protected
                    file.

                    https://www.samba.org/samba/security/CVE-2026-2340.html


 o CVE-2026-3012:   auto-enrolment GPO installing CA certificate over http
                    without verification

                    To bootstrap a certificate chain a domain member must
                    fetch a certificate without TLS. It was trusting HTTP
                    for this when a more secure encrypted LDAP channel
                    was also available.

                    https://www.samba.org/samba/security/CVE-2026-3012.html


 o CVE-2026-3238:   Denial of service against AD DC WINS server

                    The WINS server component of the Active
                    Directory Domain controller code in Samba
                    is vulnerable to a NULL pointer dereference
                    and crash caused by a unauthenticated UDP
                    packet.

                    https://www.samba.org/samba/security/CVE-2026-3238.html


 o CVE-2026-4408:   Unauthenticated Remote Code Execution in Samba DCE/RPC
 SAMR
                    server

                    Samba file servers and classic (non-AD) domain
 controllers
                    with samba-dcerpcd started as a system service and with
 a
                    "check password script" that has the %u substitution
                    character are vulnerable to a remote code execution.

                    https://www.samba.org/samba/security/CVE-2026-4408.html


 o CVE-2026-4480:   Unauthenticated Remote Code Execution in Samba printing
                    subsystem

                    Samba print servers with a "print command"
                    that has the %J substitution character
                    are vulnerable to a Remote Code Execution.

                    https://www.samba.org/samba/security/CVE-2026-4480.html


 Changes
 -------

 o  Douglas Bagnall <[email protected]>
    * BUG 15997: CVE-2026-2340
    * BUG 16003: CVE-2026-3012
    * BUG 16033: CVE-2026-4480
    * BUG 16034: CVE-2026-4408

 o  Pavel Kohout <[email protected]>
    * BUG 15997: CVE-2026-2340

 o  Volker Lendecke <[email protected]>
    * BUG 15992: CVE-2026-1933
    * BUG 16012: CVE-2026-3238

 o  Stefan Metzmacher <[email protected]>
    * BUG 15992: CVE-2026-1933
    * BUG 16033: CVE-2026-4480
    * BUG 16034: CVE-2026-4408
    * BUG 16059: (4.23-only) CVE-2026-40170: thirdparty ngtcp2 needs to be
 updated
    * BUG 16073: (4.22/23-only) Winbind can change Ownership Of / To A User
 Who
      has Homedir / In passwd

 }}}
-- 
Ticket URL: <https://wiki.linuxfromscratch.org/blfs/ticket/23163#comment:3>
BLFS Trac <https://wiki.linuxfromscratch.org/blfs/>
Beyond Linux From Scratch

-- 
http://lists.linuxfromscratch.org/sympa/info/blfs-book
Unsubscribe: See the above information page
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.