Re: [Buildroot] [PATCH 1/1] package/samba4: security bump version to 4.24.5
Julien Olivain via buildroot <[email protected]> Tue, 28 Jul 2026 20:53:46 +0200
| Newsgroups | net.busybox.buildroot |
|---|---|
| Message-ID | <[email protected]> |
On 28/07/2026 19:36, Bernd Kuhls wrote: > https://www.samba.org/samba/history/samba-4.24.5.html > > This is a security release in order to address the following defects: > > o CVE-2026-6949: > TSIG packet with name compression can crash DNS > > Incorrect size calculations when a TSIG record contains > compressed names can lead to a large out-of-bounds write > causing the server to crash. > > https://www.samba.org/samba/security/CVE-2026-6949.html > > o CVE-2026-58216: > An authenticated user could possibly crash a KDC process > > A kpasswd packet that contains malformed ASN.1 might cause > the server to access 6 bytes of unallocated memory. This > memory is not exposed to the user, but in some > circumstances the server could crash. > > https://www.samba.org/samba/security/CVE-2026-58216.html > > o CVE-2026-58218: > DNS signing DoS via TKEY name cache exhaustion > > An unauthenticated user can repeatedly register names TKEY > names, which floods a cache causing legitimate TKEYs to be > expunged. This can practically block the use DNS TSIG > signing. > > https://www.samba.org/samba/security/CVE-2026-58218.html > > o CVE-2026-58221: > Samba AD authenticated LDAP access domain takeover > > Samba AD low-privilege authenticated LDAP access allows > modifications to internal LDB special DNs, which permits a > domain takeover. > > https://www.samba.org/samba/security/CVE-2026-58221.html > > o CVE-2026-58222: > Samba AD LDAP Compare filter injection and trusted-request > confusion disclose protected attributes > > An ordinary authenticated domain user can bypass access > checks and query confidential Active Directory attributes > (such as KDS root keys) via LDAP Compare requests. Due to a > filter injection flaw and trusted execution context, the > LDAP Compare operation can be turned into a > protected-attribute disclosure oracle. > > https://www.samba.org/samba/security/CVE-2026-58222.html > > o CVE-2026-58224: > The CTDB protocol has bounds checking issues > > CTDB fails to do integrity checking of received packets. > This includes failure to check field lengths against packet > lengths when unmarshalling packets. > > https://www.samba.org/samba/security/CVE-2026-58224.html > > Signed-off-by: Bernd Kuhls <[email protected]> Applied to master, thanks. _______________________________________________ buildroot mailing list [email protected] https://lists.buildroot.org/mailman/listinfo/buildroot