Re: [BLFS Trac] #23163: samba-4.24.3 (was: samba-4.24.1)
| Newsgroups | gmane.linux.lfs.beyond.book |
|---|---|
| Message-ID | <[email protected]> |
#23163: samba-4.24.3
-------------------------+------------------------------
Reporter: Bruce Dubbs | Owner: Douglas R. Reno
Type: enhancement | Status: assigned
Priority: high | Milestone: 13.1
Component: BOOK | Version: git
Severity: normal | Resolution:
Keywords: |
-------------------------+------------------------------
Changes (by Douglas R. Reno):
* summary: samba-4.24.1 => samba-4.24.3
Comment:
Now 4.24.3.
{{{
Release Announcements
---------------------
This is a security release in order to address the following defects:
o CVE-2026-1933: Missing access checks on reparse point operations
On a share marked "read only = yes" and
on file handles opened R/O users can set
or delete the reparse point xattrs on files
that the user has write-access in the file
system for.
https://www.samba.org/samba/security/CVE-2026-1933.html
o CVE-2026-2340: WORM vfs module does not block overwrites
The WORM (Write-Once, Read Many) vfs module
is supposed to lock write access to shared
files, so they cannot be altered after initial
writes. It was allowing files to be overwritten
by renaming a newly created file over a protected
file.
https://www.samba.org/samba/security/CVE-2026-2340.html
o CVE-2026-3012: auto-enrolment GPO installing CA certificate over http
without verification
To bootstrap a certificate chain a domain member must
fetch a certificate without TLS. It was trusting HTTP
for this when a more secure encrypted LDAP channel
was also available.
https://www.samba.org/samba/security/CVE-2026-3012.html
o CVE-2026-3238: Denial of service against AD DC WINS server
The WINS server component of the Active
Directory Domain controller code in Samba
is vulnerable to a NULL pointer dereference
and crash caused by a unauthenticated UDP
packet.
https://www.samba.org/samba/security/CVE-2026-3238.html
o CVE-2026-4408: Unauthenticated Remote Code Execution in Samba DCE/RPC
SAMR
server
Samba file servers and classic (non-AD) domain
controllers
with samba-dcerpcd started as a system service and with
a
"check password script" that has the %u substitution
character are vulnerable to a remote code execution.
https://www.samba.org/samba/security/CVE-2026-4408.html
o CVE-2026-4480: Unauthenticated Remote Code Execution in Samba printing
subsystem
Samba print servers with a "print command"
that has the %J substitution character
are vulnerable to a Remote Code Execution.
https://www.samba.org/samba/security/CVE-2026-4480.html
Changes
-------
o Douglas Bagnall <[email protected]>
* BUG 15997: CVE-2026-2340
* BUG 16003: CVE-2026-3012
* BUG 16033: CVE-2026-4480
* BUG 16034: CVE-2026-4408
o Pavel Kohout <[email protected]>
* BUG 15997: CVE-2026-2340
o Volker Lendecke <[email protected]>
* BUG 15992: CVE-2026-1933
* BUG 16012: CVE-2026-3238
o Stefan Metzmacher <[email protected]>
* BUG 15992: CVE-2026-1933
* BUG 16033: CVE-2026-4480
* BUG 16034: CVE-2026-4408
* BUG 16059: (4.23-only) CVE-2026-40170: thirdparty ngtcp2 needs to be
updated
* BUG 16073: (4.22/23-only) Winbind can change Ownership Of / To A User
Who
has Homedir / In passwd
}}}
--
Ticket URL: <https://wiki.linuxfromscratch.org/blfs/ticket/23163#comment:3>
BLFS Trac <https://wiki.linuxfromscratch.org/blfs/>
Beyond Linux From Scratch
--
http://lists.linuxfromscratch.org/sympa/info/blfs-book
Unsubscribe: See the above information page